Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Published: 2026-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via reflective user input
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises when the Relevanssi ‘debug’ path echoes unescaped query variables inside a <pre> block. When an administrator turns on Debugging mode, an unauthenticated attacker can supply the parameters 's', 'post_types', or 'orderby' along with relevanssi_debug=on. The content is reflected without validation, allowing arbitrary JavaScript to execute in the victim’s browser. This will enable attackers to steal session cookies, deface content or deflect normal traffic, but requires the victim to view a page that includes the debug output, so exploitation is limited to pages where the debug mode is active.

Affected Systems

WordPress sites running the Relevanssi – A Better Search plugin up to and including version 4.28.1 are affected. Any installation that has enabled Debugging mode in the plugin’s settings is susceptible; installations that have disabled debug mode are not vulnerable.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, but the vulnerability is not listed in CISA KEV, suggesting there has been no confirmed exploitation to date. Attackers can construct a crafted link containing the vulnerable parameters and the debug flag; because no capability or nonce checks protect this path, the exploit can be performed by anyone who can trick a site visitor into clicking the link. Once triggered, the malicious script executes within the context of the site, providing the attacker full client‑side capabilities.

Generated by OpenCVE AI on September 11, 2026 at 05:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Relevanssi plugin to the latest version that removes the vulnerable debug functionality.
  • Disabling the Debugging mode setting in the Relevanssi options will prevent the insecure code path from being enabled.
  • Avoid passing relevanssi_debug=on in URLs on publicly exposed pages – remove or block this query string parameter from web requests.

Generated by OpenCVE AI on September 11, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Comesio
Comesio relevanssi – A Better Search
Wordpress
Wordpress wordpress
Vendors & Products Comesio
Comesio relevanssi – A Better Search
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.
Title Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Comesio Relevanssi – A Better Search
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T14:10:13.313Z

Reserved: 2026-08-16T13:53:20.548Z

Link: CVE-2026-19985

cve-icon Vulnrichment

Updated: 2026-09-11T14:10:03.202Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:34.620

Modified: 2026-09-11T15:17:00.737

Link: CVE-2026-19985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')