Description
The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the click-tracking and logging feature to be activated in the plugin settings, and exploitation is trivially accessible to unauthenticated users because a valid _rt_nonce is publicly emitted on every search-results page.
Published: 2026-10-02
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

The Relevanssi Premium plugin for WordPress contains an unsanitized '_rt' request parameter that is stored in the system. An attacker can inject arbitrary JavaScript code via this parameter, and the payload is persisted and executed whenever a user views the affected page. Because the injection does not require authentication, any user visiting the infected page can be exposed to malicious scripts that may steal session cookies, deface content, or compromise the browser.

Affected Systems

All WordPress sites that use Relevanssi Premium version 2.31.4 or earlier are affected. The vulnerability is present in every release of the plugin up to and including 2.31.4 and therefore any installation of that product and older patches carries the risk.

Risk and Exploitability

The CVSS score of 7.2 classifies the vulnerability as moderate‑to‑high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is effectively unauthenticated and trivially achievable because the plugin’s click‑tracking feature emits a public '_rt_nonce' on each search‑results page. An attacker can craft a malicious URL that an unsuspecting user might click, leading to the execution of the injected script without any special privileges.

Generated by OpenCVE AI on October 2, 2026 at 08:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Relevanssi Premium plugin to a version newer than 2.31.4, which removes the unsafe handling of the '_rt' parameter.
  • If an immediate update is not possible, disable the click‑tracking and logging feature in the plugin settings so that the publicly exposed '_rt_nonce' is no longer generated.
  • After disabling click‑tracking, clear any existing stored scripts from the search results page or reset the plugin’s cache to remove previously injected code.
  • As a temporary hardening step, configure the web server or a security plugin to reject requests containing the '_rt' query parameter or to sanitize its contents before processing.

Generated by OpenCVE AI on October 2, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the click-tracking and logging feature to be activated in the plugin settings, and exploitation is trivially accessible to unauthenticated users because a valid _rt_nonce is publicly emitted on every search-results page.
Title Relevanssi Premium <= 2.31.4 - Unauthenticated Stored Cross-Site Scripting via '_rt' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T07:39:25.461Z

Reserved: 2026-09-30T14:55:31.063Z

Link: CVE-2026-103426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T08:17:00.210

Modified: 2026-10-02T08:17:00.210

Link: CVE-2026-103426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T08:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')