WP Clinic
Log in Sign up

CVE · Medium

CVE-2025-14719 — Relevanssi – A Better Search [relevanssi] < 4.26.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-14719 Relevanssi – A Better Search [relevanssi] < 4.26.0 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Medium 4.9 < 4.26.0 4.26.0 2025-12-17

CVE-2025-14719

The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 (Premium) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.