<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:relevanssi:a_better_search:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arelevanssia_better_search/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:24:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arelevanssia_better_search/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Relevanssi - A Better Search WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-relevanssi-xss/</link><pubDate>Fri, 02 Oct 2026 08:24:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-relevanssi-xss/</guid><description>The Relevanssi plugin for WordPress is vulnerable to stored Cross-Site Scripting (XSS) due to insufficient input sanitization of comment content, allowing unauthenticated attackers to execute arbitrary scripts.</description><content:encoded><![CDATA[<p>The Relevanssi - A Better Search plugin for WordPress is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 4.28.3. The issue stems from insufficient input sanitization and output escaping of comment content processed by the plugin. Attackers can leverage this flaw to inject arbitrary malicious web scripts into the site's content.</p>
<p>The exploit condition is specific: it requires the site administrator to have configured the &quot;Allowable tags in excerpts&quot; setting to a non-empty value (such as the default <code>&lt;p&gt;&lt;a&gt;&lt;strong&gt;</code>). Because the plugin utilizes a prefix-matching regex for tag validation, an attacker can inject a malicious tag name if that name begins with one of the configured allowed tags. When a user, typically an administrator, accesses an page containing the injected content, the malicious script executes in their browser context, potentially leading to unauthorized actions or session compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of other users or administrators viewing the site. This may result in unauthorized administrative actions, session hijacking, or defacement. The vulnerability affects all users running Relevanssi versions 4.28.3 and older.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update the Relevanssi - A Better Search plugin to the latest available version (beyond 4.28.3) where input sanitization has been corrected.</li>
<li>Review the &quot;Allowable tags in excerpts&quot; setting in the WordPress administrative console and remove unnecessary or permissive tags that could facilitate prefix-matching bypasses.</li>
<li>Audit WordPress comment logs for suspicious HTML or script injection patterns if the plugin has been active with broad tag allowances.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>xss</category></item></channel></rss>