CVE-2025-4396

HIGH EXPLOITED NUCLEI

Relevanssi - A Better Search <4.24.4, <=2.27.4 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-4396 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including sup3rDav3, Nefhara. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2025-4396, a time-based blind SQL injection vulnerability in the Relevanssi WordPress plugin. The exploit includes both manual and automated approaches to bypass comma filtering and greedy sleep behavior in hardened environments.

Description

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.

Exploits (2)

nomisec WORKING POC
by sup3rDav3 · poc
https://github.com/sup3rDav3/CVE-2025-4396

This repository contains a functional proof-of-concept exploit for CVE-2025-4396, a time-based blind SQL injection vulnerability in the Relevanssi WordPress plugin. The exploit includes both manual and automated approaches to bypass comma filtering and greedy sleep behavior in hardened environments.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Relevanssi WordPress plugin 4.24.4
No auth needed
Prerequisites: Target running Relevanssi 4.24.4 · Access to the vulnerable endpoint
devstral-2 · analyzed May 10, 2026 Full analysis →
nomisec WORKING POC
by Nefhara · poc
https://github.com/Nefhara/CVE-2025-4396

This repository contains a functional Python script for offline cracking of WordPress 6.8+ password hashes, which use a custom format involving HMAC-SHA384 and bcrypt. The script automates the process by pre-hashing wordlists and using Hashcat to recover passwords.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress 6.8+
No auth needed
Prerequisites: WordPress 6.8+ password hash · wordlist file · Hashcat installed
devstral-2 · analyzed Mar 19, 2026 Full analysis →

Nuclei Templates (1)

Relevanssi <= 4.24.4 (Free) - Unauthenticated SQL Injection
HIGHVERIFIEDby iamnoooob,rootxharsh,pdresearch

Scores

CVSS v3 7.5
EPSS 0.2197
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2026-02-02
CWE
CWE-89
Status published
Products (4)
comesio/Relevanssi – A Better Search < 4.24.4
msaari/Relevanssi – A Better Search < 4.24.4
Relevanssi/Relevanssi Premium < 2.27.5
Relevanssi/Relevanssi – A Better Search (Pro) < 2.27.4
Published May 13, 2025
Tracked Since Feb 18, 2026