Stored XSS in Relevanssi - A Better Search WordPress Plugin
The Relevanssi plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) due to insufficient input sanitization of comment content, allowing unauthenticated attackers to execute arbitrary scripts.
CVE search metadata
CVE search record: CVE-2026-97641. Severity: high. CVSS: 7.2. KEV: no. Product: Relevanssi – A Better Search (<= 4.28.3). Brief: Stored XSS in Relevanssi - A Better Search WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-relevanssi-xss/
The Relevanssi - A Better Search plugin for WordPress is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 4.28.3. The issue stems from insufficient input sanitization and output escaping of comment content processed by the plugin. Attackers can leverage this flaw to inject arbitrary malicious web scripts into the site's content.
The exploit condition is specific: it requires the site administrator to have configured the "Allowable tags in excerpts" setting to a non-empty value (such as the default <p><a><strong>). Because the plugin utilizes a prefix-matching regex for tag validation, an attacker can inject a malicious tag name if that name begins with one of the configured allowed tags. When a user, typically an administrator, accesses an page containing the injected content, the malicious script executes in their browser context, potentially leading to unauthorized actions or session compromise.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users or administrators viewing the site. This may result in unauthorized administrative actions, session hijacking, or defacement. The vulnerability affects all users running Relevanssi versions 4.28.3 and older.
Recommendation
Prioritized actions for security teams:
- Update the Relevanssi - A Better Search plugin to the latest available version (beyond 4.28.3) where input sanitization has been corrected.
- Review the "Allowable tags in excerpts" setting in the WordPress administrative console and remove unnecessary or permissive tags that could facilitate prefix-matching bypasses.
- Audit WordPress comment logs for suspicious HTML or script injection patterns if the plugin has been active with broad tag allowances.
Mitigations
Upgrade Relevanssi - A Better Search plugin to a version later than 4.28.3.
CVE-2026-97641