Relevanssi – A Better Search

Relevanssi – A Better Search has 19 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; all 19 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2024 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (42%). Other recurring categories include SQL Injection, Missing Authorization.

Every one of the 19 issues recorded for Relevanssi – A Better Search has a vendor fix available, so running the current release closes all known holes.

12 independent researchers contributed these findings, most of them (3) reported by Jack Taylor. Relevanssi – A Better Search is installed on roughly 100,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891030.06.2009Today25.02.20149.8Relevanssi <= 3.3 - SQL Injection CVSS 9.8 · 25.02.201403.01.20156.1Relevanssi – A Better Search < 3.3.8 - Cross-Site Scripting CVSS 6.1 · 03.01.201528.02.20176.1Relevanssi – A Better Search <= 3.5.7.1 - Stored Cross-Site Scripting CVSS 6.1 · 28.02.201730.03.20185.4Relevanssi <= 4.0.4 - Cross-Site Scripting CVSS 5.4 · 30.03.201810.04.20188.7Relevanssi <= 3.6.0 - Authenticated (Admin+) SQL Injection CVSS 8.7 · 10.04.201819.10.20217.2Relevanssi - A Better Search Free & Premium <= 2.16.3 & 4.14.3 - Stored Cross-Site Scripting CVSS 7.2 · 19.10.202115.02.20226.3Relevanssi – A Better Search < 4.14.6 & Relevanssi – A Better Search Pro < 2.16.5 - Missing Authorization CVSS 6.3 · 15.02.202204.01.20245.3Relevanssi <= 4.21.2 (Free) and < 2.25.0 (Premium) - Missing Authorization to Unauthorized Post Access CVSS 5.3 · 04.01.202422.02.20245.3Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export CVSS 5.3 · 22.02.202404.04.20245.8Relevanssi – A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection CVSS 5.8 · 04.04.20245.3Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update CVSS 5.3 · 04.04.202415.08.20245.3Relevanssi <= 4.22.2 (Free) and <= 2.25.1 (Premium) - Unauthenticated Information Exposure CVSS 5.3 · 15.08.202417.09.20246.4Relevanssi – A Better Search <= 4.23.0 (Free) and <= 2.26.0 (Premium) - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.09.202406.05.20256.1Relevanssi <= 4.24.3 (Free) and <= 2.27.4 (Premium) - Unauthenticated Stored Cross-Site Scripting via Search Highlights CVSS 6.1 · 06.05.202512.05.20257.5Relevanssi <= 4.24.4 (Free) and <= 2.27.5 (Premium) - Unauthenticated SQL Injection CVSS 7.5 · 12.05.202530.05.20254.7Relevanssi <= 4.24.5 (Free) and <= 2.27.6 (Premium) - Unauthenticated Stored Cross-Site Scripting via Excerpt Highlights CVSS 4.7 · 30.05.202517.12.20256.5Relevanssi < 4.26.0 (Free) < 2.29.0 (Premium) - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 17.12.202504.08.20266.5Relevanssi <= 4.27.1 and Relevanssi Premium <= 2.30.2 - Authenticated (Contributor+) SQL Injection CVSS 6.5 · 04.08.202610.09.20266.1Relevanssi <= 4.28.1 - Reflected Cross-Site Scripting CVSS 6.1 · 10.09.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

19

Get automatic notifications for all Relevanssi – A Better Search vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

Relevanssi <= 3.3 - SQL Injection

Read the full analysis

Vulnerability Records

19 records
2026-09-10 14:41CVE-2026-19985
6.1
Medium
MutantgunYes
2026-08-04 16:34CVE-2026-15941
6.5
Medium
darooYes
2025-12-17 00:00CVE-2025-14719
6.5
Medium
Drew Webber (mcdruid)Yes
2025-05-30 14:49CVE-2025-5016
4.7
Medium
Jack TaylorYes
2025-05-12 14:38CVE-2025-4396
7.5
High
Jack TaylorYes
2025-05-06 13:45CVE-2025-4054
6.1
Medium
Jack TaylorYes
2024-09-17 00:00CVE-2024-9021
6.4
Medium
Krugov ArtyomYes
2024-08-15 13:29CVE-2024-7630
5.3
Medium
stealthcopterYes
2024-04-04 00:00CVE-2024-3214
5.8
Medium
Thura Moe Myint (mgthuramoemyint)Yes
2024-04-04 00:00CVE-2024-3213
5.3
Medium
Thura Moe Myint (mgthuramoemyint)Yes
Showing 1–10 of 19 reports
Relevanssi – A Better Search banner
Latestv4.28.3

Relevanssi – A Better Search

Christoph Vielgrader

Author

Christoph Vielgrader

4.8(405)
96/100
Last Updated
2026-09-10 (3d ago)
Active Installs
100,000+
Downloads
8,276,086
Requires WP
4.9+
Requires PHP
7.1+
Tested up to
WP 7.1
Created
2009-06-30 (17y ago)

Relevanssi replaces the standard WordPress search with a better search engine, with lots of features and configurable options. You’ll get better results, better presentation of results – your users will thank you. This is the free version of Relevanssi. There’s also Relevanssi Premium, which has added features. For more information about Premium, see Relevanssi.com. Do note that using Relevanssi may require large amounts (hundreds of megabytes) of database space (for a reasonable estimate, multiply the size of your wp_posts database table by three). If your hosting setup has a limited amount of space for database tables, using Relevanssi may cause problems. In those cases use of Relevanssi cannot be recommended. Key features Search results sorted in the order of relevance, not by date. Fuzzy matching: match partial words, if complete words don’t match. Find documents matching either just one search term (OR query) or require all words to appear (AND query). Search for phrases with quotes, for example “search phrase”. Create custom excerpts that show where the hit was made, with the search terms highlighted. Highlight search terms in the documents when user clicks through search results. Search comments, tags, categories and custom fields. Multisite friendly. bbPress support. Gutenberg friendly. Advanced features Adjust the weighting for titles, tags and comments. Log queries, show most popular queries and recent queries with no hits. Restrict searches to categories and tags using a hidden variable or plugin settings. Index custom post types and custom taxonomies. Index the contents of shortcodes. Google-style “Did you mean?” suggestions based on successful user searches. Support for WPML multi-language plugin and Polylang. Support for s2member membership plugin, Members, Groups, Simple Membership and other membership plugins. Advanced filtering to help hacking the search results the way you want. Search result throttling to improve performance on large databases. Disable indexing of post content and post titles with a simple filter hook. Premium features (only in Relevanssi Premium) Indexing attachment content (PDF, Office, Open Office). Improved spelling correction in “Did you mean?” suggestions. Searching across multiple sites in the same multisite installation. Search and index user profiles. Search and index taxonomy term pages (categories, tags, custom taxonomies). Search and index arbitrary columns in wp_posts MySQL table. Assign weights to any post types and taxonomies. Assign extra weight to new posts. Let the user choose between AND and OR searches, use + and – operator (AND and NOT). Export and import settings. WP CLI commands. Related posts. Redirects for searches. Thanks Cristian Damm for tag indexing, comment indexing, post/page exclusion and general helpfulness. Marcus Dalgren for UTF-8 fixing. Warren Tape for 2.5.5 fixes. Mohib Ebrahim for relentless bug hunting. John Calahan for extensive 4.0 beta testing.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C