Sceawere
Vulnerability Detail
CVE-2026-97641UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Relevanssi Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- comesio
- Product
- Relevanssi – A Better Search
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has configured a non-empty value for the "Allowable tags in excerpts" setting, such as the default example value of <p><a><strong>, as the prefix-matching regex must have an allowable tag whose name is a prefix of the injected tag name.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:05.837Z",
"pubdate": "2026-10-02T08:17:05.837Z",
"executiveSummary": "Relevanssi – A Better Search for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping. This flaw, affecting versions up to and including 4.28.3, permits unauthenticated attackers to inject malicious JavaScript into comment content, which subsequently executes within the browser context of any user viewing the affected page.\nThe vulnerability is contingent upon a specific administrative configuration: the 'Allowable tags in excerpts' setting must contain non-empty values. Because the underlying sanitization mechanism employs a flawed prefix-matching regex, attackers can bypass security controls if an injected tag name shares a prefix with an approved tag defined in the settings. Successful exploitation enables unauthorized script execution, potentially leading to administrative session hijacking, credential theft, or the compromise of sensitive user information. Given the nature of Stored XSS, the payload persists on the server, ensuring that every user loading the compromised content triggers the malicious script, posing a significant risk to the integrity and confidentiality of the WordPress environment.",
"technicalDetails": "The vulnerability originates from inadequate sanitization of comment content within the Relevanssi plugin. When the plugin processes excerpts for search results, it relies on an allow-list-based filtering mechanism governed by the 'Allowable tags in excerpts' setting. The root cause is a flawed regular expression implementation used to validate HTML tags. This regex utilizes prefix-matching logic that fails to verify the entire string of the injected tag, instead only confirming that the beginning of the tag matches a permitted element.\nFor example, if the administrator has configured '<p>' as an allowable tag, the regex will permit any tag that starts with 'p'. An attacker can exploit this by crafting a malicious payload using an injected tag like '<pre...>', which is permitted by the regex because it shares the 'p' prefix. This bypass allows the injection of arbitrary HTML and JavaScript attributes, such as 'onmouseover', 'onerror', or 'onload', into the comment field.\nThe attack flow proceeds as follows: First, the unauthenticated attacker identifies a public-facing comment section on a WordPress site utilizing the Relevanssi plugin. Second, the attacker submits a comment containing a crafted HTML payload designed to bypass the prefix-matching filter. Third, the plugin, during its excerpt generation process, fails to properly sanitize the payload, storing the malicious script directly into the database. Fourth, whenever a user (including privileged administrators) views search results containing the injected excerpt, the browser parses the malicious HTML. Fifth, the payload executes in the context of the victim's session.\nBecause the payload is stored, this is a classic Stored XSS attack. The technical impact includes, but is not limited to, the exfiltration of session cookies (if 'HttpOnly' flags are not strictly enforced), the execution of unauthorized administrative actions (Cross-Site Request Forgery via XSS), and the redirection of users to malicious third-party domains. Since the vulnerability does not require authentication to the WordPress dashboard, it presents a broad attack surface, accessible to any user capable of posting a comment. The lack of robust context-aware output encoding ensures that the browser interprets the injected data as executable code rather than plain text, completing the exploitation chain."
}