What the vulnerability does
01Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Explanation of Vulnerability in Simple Terms
02Summary
Relevanssi Premium versions up to 2.25.1 contain an integrity vulnerability that allows network-based modification of data without authentication. The vulnerability has a changed scope, meaning the impact may extend beyond the vulnerable component itself. No confidentiality or availability impact is present. Site administrators should update to a version newer than 2.25.1.
What an attacker can do
03Attacker Capabilities
Modify data on the site without needing to log in or interact with a user.
Potential impact on your site
04Site Impact
Attackers can alter site content or data without credentials, potentially affecting site integrity and user trust.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
April 9, 2024
CVE published
April 8, 2026
Record updated