rootpwn

high · CVSS v3 7.2 · EPSS 0.00241

CVE-2026-97641

The Relevanssi WordPress plugin is vulnerable to stored XSS via comment content. Attackers can inject scripts that run when users view pages

Overview

The Relevanssi WordPress plugin is vulnerable to stored XSS via comment content. Attackers can inject scripts that run when users view pages. The flaw exists in all versions up to 4.28.3 when the 'Allowable tags in excerpts' setting is non-empty.

Description

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has configured a non-empty value for the "Allowable tags in excerpts" setting, such as the default example value of , as the prefix-matching regex must have an allowable tag whose name is a prefix of the injected tag name.

Impact

Confidentiality: attackers can exfiltrate user data via injected scripts. Integrity: malicious scripts can modify page content. Availability: repeated script execution may degrade performance. Defenders: site administrators and users of WordPress sites running Relevanssi <=4.28.3.

Remediation

Upgrade Relevanssi to 4.28.4 or later. If upgrade not possible, set 'Allowable tags in excerpts' to empty or restrict to safe tags. Sanitize comment content or disable comment functionality. Monitor for injected scripts.

Risk context

Severity is high (CVSS 7.2) but EPSS indicates low likelihood of exploitation. Sites with the vulnerable plugin should address promptly.

Affected products

  • WordPress
  • Relevanssi plugin
  • Relevanssi <=4.28.3
  • Relevanssi 4.28.3
  • WordPress plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00241

XSS WordPress Relevanssi Stored XSS Comment Injection High Severity EPSS

← All CVEs