CVE · Medium

CVE-2023-7199 — Relevanssi – A Better Search [relevanssi] < 4.22.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-7199 Relevanssi – A Better Search [relevanssi] < 4.22.0 Authorization Bypass Through User-Controlled Key Medium 5.3 < 4.22.0 4.22.0 2024-01-04

CVE-2023-7199

The Relevanssi plugin versions 4.21.2 and below for the free edition, and 2.24.9 and below for the premium edition, contain a vulnerability allowing unauthenticated users to access private and draft posts through improper validation of user-supplied parameters. An attacker could exploit this flaw to retrieve sensitive information contained within unpublished content without requiring authentication credentials. The issue affects the plugin's search functionality and its handling of restricted post types.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.