Junglewise Threat Intelligence

CVE-2026-15941: Relevanssi SQL injection in Admin Search

CVE-2026-15941 · Severity: medium · CVSS 6.5 · Published 2026-08-05

Executive brief

Relevanssi is a popular WordPress search plugin that provides an Admin Search page for logged-in users. The Admin Search feature contains a SQL injection vulnerability that allows an authenticated contributor-level attacker to inject malicious SQL code through the search interface and extract sensitive data from the WordPress database, such as user credentials or private content.

Technical details

This is a SQL injection vulnerability in Relevanssi's AJAX handler for the Admin Search feature. The vulnerability exists in the taxonomy query builder: user-controlled taxonomy values from the `args` parameter are sanitized as text but are not parameterized before being interpolated directly into a term taxonomy lookup SQL query. An authenticated attacker with the `edit_posts` capability (contributor-level or higher) can exploit this via the AJAX endpoint to execute time-based blind SQL injection attacks. The vulnerable code is in the taxonomy restriction builder that processes taxonomy data passed through the Admin Search request. Fixes and patches are likely available from the Relevanssi development team.

Affected products

  • Relevanssi Relevanssi before 4.27.1

Timeline

  • 2026-08-05: disclosed

References