Stored Cross-Site Scripting Vulnerability in Relevanssi Premium for WordPress
CVE-2026-103426
7.2HIGH
What is CVE-2026-103426?
The Relevanssi Premium plugin for WordPress is susceptible to a Stored Cross-Site Scripting flaw due to inadequate input sanitization and output escaping of the '_rt' parameter. As a result, unauthenticated attackers can inject arbitrary web scripts that execute when a user accesses an affected page. This vulnerability is particularly concerning as it requires the click-tracking and logging feature to be enabled, and exploitation is made easier by the generation and public emission of a valid _rt_nonce on every search-results page.
Affected Version(s)
Relevanssi Premium 0 <= 2.31.4