SQL Injection Vulnerability in Relevanssi WordPress Plugin
CVE-2026-15941
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-15941?
The Relevanssi plugin for WordPress is vulnerable to SQL injection via its Admin Search page, which allows authenticated users with edit_posts capability to perform searches. The AJAX handler of the plugin accepts a user-controlled args parameter, which is parsed into a WP_Query. While the taxonomy value is sanitized as text, it is not properly parameterized for SQL prior to being used in a term taxonomy lookup query. This flaw enables an authenticated contributor-level user to manipulate the AJAX request, leading to the execution of time-based blind SQL injection attacks against the WordPress database.
Affected Version(s)
Relevanssi β A Better Search 0 <= 4.27.1
Relevanssi Premium β A Better Search 0 <= 2.30.2