Vulnerability Description
The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/admin-ajax
- https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search-tax
- https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.1/lib/search.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4f96b87a-1405-4cf6-b90
FAQ
What is CVE-2026-15941?
CVE-2026-15941 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` param...
How severe is CVE-2026-15941?
CVE-2026-15941 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15941?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.