The Relevanssi – A Better Search plugin for WordPress is...
Moderate severity
Unreviewed
Published
Apr 9, 2024
to the GitHub Advisory Database
•
Updated Jan 28, 2025
Description
Published by the National Vulnerability Database
Apr 9, 2024
Published to the GitHub Advisory Database
Apr 9, 2024
Last updated
Jan 28, 2025
The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
References