Junglewise Threat Intelligence

CVE-2026-19985: Relevanssi A Better Search reflected cross-site scripting

CVE-2026-19985 · Severity: medium · CVSS 6.1 · Published 2026-09-11

Executive brief

Relevanssi is a popular WordPress plugin that provides enhanced search functionality for WordPress sites. An unauthenticated attacker can inject malicious JavaScript into pages viewed by site visitors by crafting a specially designed link, potentially stealing user credentials, session tokens, or performing unauthorized actions on behalf of the victim. This attack requires the attacker to trick a user into clicking the malicious link and requires the site administrator to have debugging mode enabled in plugin settings.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in the relevanssi_debug_array() function (lib/debug.php) that occurs when the debug feature is triggered via the relevanssi_debug=on request parameter. User-supplied values from the 's', 'post_types', and 'orderby' parameters are passed to print_r() and output inside a <pre> block without HTML escaping. The debug endpoint lacks authentication checks, nonce verification, or capability checks, allowing any unauthenticated attacker to trigger it. An attacker can inject arbitrary HTML/JavaScript by crafting a malicious query string; the payload executes in the victim's browser when they visit the link if the site admin has debugging enabled. The fix is available in versions after 4.28.1.

Affected products

  • Relevanssi A Better Search up to and including 4.28.1

Timeline

  • 2026-09-11: disclosed

References