S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 14, 2025

CVE-2025-4396 Scanner

CVE-2025-4396 Scanner - SQL Injection vulnerability in Relevanssi

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
6k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-4396
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags query parameters in all versions up to, and including, 4.24.4 (Free) and <= 2.27.5 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries to already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Relevanssi Premiumby Relevanssi
0
Relevanssi – A Better Searchby comesio
0
Updated Sep 9, 2026View on NVD →
Detail

The Relevanssi plugin is widely used to enhance search functionality within WordPress websites, offering features that improve search results relevancy and configurability. It serves a crucial role for website administrators seeking to enhance user search experience, and is utilized by individual bloggers as well as large enterprises implementing WordPress on extensive platforms. It integrates seamlessly with existing WordPress installations, delivering advanced search capabilities which exceed the default functionalities. However, as with many plugins, it requires regular security evaluations to ensure protection against emerging vulnerabilities. Organizations and users rely on its safety and efficiency to maintain the integrity of their web searches. Given its popularity, any vulnerabilities within Relevanssi can pose a significant security risk, impacting a large number of users worldwide.

The SQL Injection vulnerability in the Relevanssi plugin allows unauthorized attackers to manipulate database queries through insufficiently sanitized inputs. Attackers exploit this by appending arbitrary SQL code through input fields, such as 'cats' and 'tags' parameters, which are inadequately escaped. This security flaw can lead to unauthorized database operations, risking data exposure or corruption without requiring user interaction. Due to its high severity, this vulnerability allows for the disclosure of sensitive information, bypassing traditional security measures by exploiting database queries. Understanding and mitigating this vulnerability is critical in safeguarding the data integrity of WordPress sites using Relevanssi. The nature of SQL injections means that the attacker may indirectly access the database, which houses confidential operational or personal data.

The vulnerability targets parameters and endpoints within Relevanssi where user inputs, specifically 'cats' and 'tags', are not properly sanitized before being processed by SQL queries. Attackers craft input strings to manipulate existing SQL commands, exploiting the time-based aspect to verify successful injection. Technically, by issuing a command such as 'sleep', attackers can manipulate response times confirming vulnerability presence. The exploitation does not require authentication, making it accessible to remote attackers and heightening the risk level. This SQL manipulation highlights a gap in input validation, as well as inadequate escape mechanisms prior to database query executions. As a result, regulatory compliance and best practices for input handling are crucial for bolstering defenses against such attacks.

If exploited, attackers could gain unauthorized access to sensitive information within the WordPress database, leading to issues such as data breaches or exposure of confidential user or operational data. The effects could include unauthorized data extraction, corruption of existing entries, and potential downtime as systems respond to unauthorized queries. For businesses relying on WordPress for commerce or customer engagement, customer trust and operational integrity could be compromised, resulting in reputational damage. Financial losses could arise from necessary response measures, such as system overhauls, compensations, or legal repercussions due to data privacy violations. Therefore, addressing this vulnerability stands as a critical task for administrators managing Relevanssi-enhanced WordPress sites.

REFERENCES

Solution Advice
  • Update Relevanssi to the latest version where this vulnerability is fixed.
  • Implement input validation and output encoding for all user inputs in WordPress plugins.
  • Regularly audit and update plugins to mitigate potential exposure to vulnerabilities.
  • Consider deploying a Web Application Firewall (WAF) to block SQL injection attempts.
  • Review and apply the least privilege policy for the database user accounts accessing WordPress databases.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-4396 Scanner - SQL Injection vulnerability in Relevanssi | S4E