Impact
The Relevanssi – A Better Search plugin for WordPress contains a time‑based SQL injection vulnerability triggered by the cats and tags query parameters. This flaw stems from insufficient escaping of user‑supplied input and the lack of prepared statements. An attacker who can send requests to the plugin’s search functionality can inject additional SQL commands and retrieve sensitive data from the database, such as site content or user information.
Affected Systems
WordPress installations that employ the Relevanssi – A Better Search plugin are vulnerable. The flaw affects all free releases up to and including version 4.24.4 and all premium releases up to and including version 2.27.5. Site administrators should verify whether their instance uses either of these version ranges and whether the plugin is the premium or free edition.
Risk and Exploitability
The CVSS score of 7.5 highlights a high severity risk, and the 22% EPSS score indicates a relatively frequent chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the attack vector is likely through unauthenticated HTTP requests containing maliciously crafted cats or tags parameters. Because the flaw allows unauthenticated attackers to append SQL statements to existing queries, it can lead to unprotected data extraction if exploited.
OpenCVE Enrichment