{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3arelevanssia_better_search/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:relevanssi:a_better_search:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-97641"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Relevanssi – A Better Search (\u003c= 4.28.3)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["Relevanssi"],"content_html":"\u003cp\u003eThe Relevanssi - A Better Search plugin for WordPress is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 4.28.3. The issue stems from insufficient input sanitization and output escaping of comment content processed by the plugin. Attackers can leverage this flaw to inject arbitrary malicious web scripts into the site's content.\u003c/p\u003e\n\u003cp\u003eThe exploit condition is specific: it requires the site administrator to have configured the \u0026quot;Allowable tags in excerpts\u0026quot; setting to a non-empty value (such as the default \u003ccode\u003e\u0026lt;p\u0026gt;\u0026lt;a\u0026gt;\u0026lt;strong\u0026gt;\u003c/code\u003e). Because the plugin utilizes a prefix-matching regex for tag validation, an attacker can inject a malicious tag name if that name begins with one of the configured allowed tags. When a user, typically an administrator, accesses an page containing the injected content, the malicious script executes in their browser context, potentially leading to unauthorized actions or session compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users or administrators viewing the site. This may result in unauthorized administrative actions, session hijacking, or defacement. The vulnerability affects all users running Relevanssi versions 4.28.3 and older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Relevanssi - A Better Search plugin to the latest available version (beyond 4.28.3) where input sanitization has been corrected.\u003c/li\u003e\n\u003cli\u003eReview the \u0026quot;Allowable tags in excerpts\u0026quot; setting in the WordPress administrative console and remove unnecessary or permissive tags that could facilitate prefix-matching bypasses.\u003c/li\u003e\n\u003cli\u003eAudit WordPress comment logs for suspicious HTML or script injection patterns if the plugin has been active with broad tag allowances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:24:53Z","date_published":"2026-10-02T08:24:53Z","id":"https://feed.craftedsignal.io/briefs/2026-10-relevanssi-xss/","summary":"The Relevanssi plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) due to insufficient input sanitization of comment content, allowing unauthenticated attackers to execute arbitrary scripts.","title":"Stored XSS in Relevanssi - A Better Search WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-relevanssi-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:relevanssi:a_better_search:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}