Impact
The vulnerability arises when the Relevanssi ‘debug’ path echoes unescaped query variables inside a <pre> block. When an administrator turns on Debugging mode, an unauthenticated attacker can supply the parameters 's', 'post_types', or 'orderby' along with relevanssi_debug=on. The content is reflected without validation, allowing arbitrary JavaScript to execute in the victim’s browser. This will enable attackers to steal session cookies, deface content or deflect normal traffic, but requires the victim to view a page that includes the debug output, so exploitation is limited to pages where the debug mode is active.
Affected Systems
WordPress sites running the Relevanssi – A Better Search plugin up to and including version 4.28.1 are affected. Any installation that has enabled Debugging mode in the plugin’s settings is susceptible; installations that have disabled debug mode are not vulnerable.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is not available, but the vulnerability is not listed in CISA KEV, suggesting there has been no confirmed exploitation to date. Attackers can construct a crafted link containing the vulnerable parameters and the debug flag; because no capability or nonce checks protect this path, the exploit can be performed by anyone who can trick a site visitor into clicking the link. Once triggered, the malicious script executes within the context of the site, providing the attacker full client‑side capabilities.
OpenCVE Enrichment