Cross-Site Scripting
7 records41.2%First: 2015. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 17 vulnerability records associated with Relevanssi – A Better Search, published between 2014 and 2025.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2015 | 1 | |
| 2017 | 1 | |
| 2018 | 2 | |
| 2021 | 1 | |
| 2022 | 1 | |
| 2024 | 6 | |
| 2025 | 4 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 5.9% |
| High | 3 | 17.6% |
| Medium | 13 | 76.5% |
First: 2015. Latest: 2025.
First: 2014. Latest: 2025.
First: 2022. Latest: 2024.
First: 2024. Latest: 2024.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.26.04.24.64.24.54.24.44.23.14.23.04.22.24.22.14.22.04.14.64.14.43.6.14.0.53.5.83.3.83.3.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
[*, 4.26.0) | Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection | December 17, 2025 | 4.26.0 | Medium |
*-4.24.5 | Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights | May 30, 2025 | 4.24.6 | Medium |
*-4.24.4 | Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection | May 12, 2025 | 4.24.5 | High |
*-4.24.3 | Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights | May 6, 2025 | 4.24.4 | Medium |
*-4.23.0 | Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting | September 17, 2024 | 4.23.1 | Medium |
*-4.22.2 | Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure | August 15, 2024 | 4.23.0 | Medium |
*-4.22.1 | Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update | April 4, 2024 | 4.22.2 | Medium |
*-4.22.1 | Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection | April 4, 2024 | 4.22.2 | Medium |
*-4.22.0 | Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export | February 22, 2024 | 4.22.1 | Medium |
*-4.21.2 | Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access | January 4, 2024 | 4.22.0 | Medium |
[*, 4.14.6) | Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 - Missing Authorization | February 15, 2022 | 4.14.6 | Medium |
[*, 4.14.3) | Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting | October 19, 2021 | 4.14.4 | High |
[*, 3.6.1) | Relevanssi <= 3.6.0 - Authenticated (Admin+) SQL Injection | April 10, 2018 | 3.6.1 | High |
*-4.0.4 | Relevanssi <= 4.0.4 - Cross-Site Scripting | March 30, 2018 | 4.0.5 | Medium |
[*, 3.5.8) | Relevanssi – A Better Search <= 3.5.7.1 - Stored Cross-Site Scripting | February 28, 2017 | 3.5.8 | Medium |
[*, 3.3.8) | Relevanssi – A Better Search < 3.3.8 - Cross-Site Scripting | January 3, 2015 | 3.3.8 | Medium |
*-3.3 | Relevanssi <= 3.3 - SQL Injection | February 25, 2014 | 3.3.1 | Critical |
Selected source records
Published: December 17, 2025
Published: May 30, 2025
Published: May 12, 2025
Published: May 6, 2025
Published: September 17, 2024
Published: August 15, 2024
Published: April 4, 2024
Published: April 4, 2024
Published: February 25, 2014
Published: April 10, 2018
Published: May 12, 2025
Published: October 19, 2021
Published: December 17, 2025
Published: September 17, 2024
Published: February 15, 2022
Published: February 28, 2017
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.