CVE-2024-7630: Relevanssi

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.22.2 (Free) and 2.25.1 (Premium) via the relevanssi_do_query() due to insufficient limitations on the posts that are returned when searching. This makes it possible for unauthenticated attackers to extract potentially sensitive information from password protected posts.

Affected products

  • Relevanssi Relevanssi: before 4.23.0 (fixed in 4.23.0)

Published 2024-08-16. Last modified 2026-06-17.