PT-2026-89753 · Comesio · Relevanssi – A Better Search

·

CVE-2026-19985

·

Published

2026-09-11

·

Updated

2026-09-11

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi debug array() function in lib/debug.php, which dumps user-supplied query variables through print r() inside a
 block without HTML escaping. The debug path is enabled by supplying the relevanssi debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19985

Affected Products

Relevanssi – A Better Search