Impact
The Relevanssi Premium plugin for WordPress contains an unsanitized '_rt' request parameter that is stored in the system. An attacker can inject arbitrary JavaScript code via this parameter, and the payload is persisted and executed whenever a user views the affected page. Because the injection does not require authentication, any user visiting the infected page can be exposed to malicious scripts that may steal session cookies, deface content, or compromise the browser.
Affected Systems
All WordPress sites that use Relevanssi Premium version 2.31.4 or earlier are affected. The vulnerability is present in every release of the plugin up to and including 2.31.4 and therefore any installation of that product and older patches carries the risk.
Risk and Exploitability
The CVSS score of 7.2 classifies the vulnerability as moderate‑to‑high severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The attack vector is effectively unauthenticated and trivially achievable because the plugin’s click‑tracking feature emits a public '_rt_nonce' on each search‑results page. An attacker can craft a malicious URL that an unsuspecting user might click, leading to the execution of the injected script without any special privileges.
OpenCVE Enrichment