Executive brief
Relevanssi Light is a WordPress plugin used to provide fast and efficient search functionality for websites. A critical security flaw allows unauthenticated attackers to perform SQL injection attacks, which could lead to the theft of sensitive database information or unauthorized access to the site's backend. This vulnerability is particularly dangerous as it can be exploited remotely without any user interaction or login credentials.
Technical details
A SQL injection vulnerability exists in the Relevanssi Light plugin for WordPress in versions up to and including 1.2.2. The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing an unauthenticated attacker to append malicious SQL queries. This can be exploited over the network without any prior authentication or user interaction. Successful exploitation could allow an attacker to extract sensitive data from the database, such as user credentials or site configuration details. The issue is addressed in version 1.2.3.
Affected products
- Christoph Vielgrader Relevanssi Light <= 1.2.2
Timeline
- 2026-05-16: other: Reported by ParkHyunWoo
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD dataset