vendor:
Relevanssi Wordpress Search Plugin
by:
Stefan Broeder
5.4
CVSS
MEDIUM
Reflected Cross Site Scripting (XSS)
79
CWE
Product Name: Relevanssi Wordpress Search Plugin
Affected Version From: 4.0.0
Affected Version To: 4.0.4
Patch Exists: YES
Related CWE: CVE-2018-9034
CPE: a:relevanssi:relevanssi:4.0.4
Platforms Tested: WordPress
2018
Relevanssi WordPress Search Plugin Reflected Cross Site Scripting (XSS)
Relevanssi is a WordPress plugin with more than 100.000 active installations. Version 4.0.4 (and possibly previous versions) are affected by a Reflected XSS vulnerability. Arbitrary JavaScript code can be run on browser side if a logged in WordPress administrator is tricked to click on a link or browse a URL under the attacker control. This can potentially lead to creation of new admin users, or remote code execution on the server.
Mitigation:
Update to the latest version of Relevanssi plugin (4.0.5 or higher).