Impact
WordPress sites that have installed Relevanssi Light plugin version 1.2.2 or earlier are vulnerable to an unauthenticated SQL Injection flaw. The defect allows an attacker to supply crafted input through the plugin’s search interface, which is directly inserted into an SQL query without proper sanitization. If exploited, the attacker can read sensitive database tables, modify data, or cause administrative operations, thereby compromising data confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects sites running WordPress with the Relevanssi Light plugin by Christoph Vielgrader. All releases from the latest 1.2.2 downgrade upward, including any 1.2.x version prior to the fixed 1.2.3, are impacted. Site administrators must verify the plugin version and ensure any vulnerable copy is removed or upgraded.
Risk and Exploitability
The advisory assigns a CVSS score of 9.3, indicating critical severity. The EPSS score is 0.00236, indicating a very low but non-zero exploitation probability; the absence of a KEV listing likewise does not reduce the risk. Attackers can reach the vulnerable endpoint over the public web interface; authentication is not required. The flaw is a classic input-validation weakness (CWE‑89). Given the high score and the unrestricted access, the vulnerability should be considered highly exploitable and is likely to be a priority target for malicious actors.
OpenCVE Enrichment