CVE-2025-4396 is a high-severity time-based SQL Injection vulnerability affecting the Relevanssi – A Better Search plugin for WordPress, specifically versions up to 4.24.4 (Free) and 2.27.4 (Premium). This flaw allows unauthenticated attackers to extract sensitive database information by manipulating the 'cats' and 'tags' query parameters. With a CVSS score of 7.5 (HIGH), the exploit requires no user interaction and has a low attack complexity, posing a significant risk to confidentiality. While not yet in CISA's KEV catalog, a Nuclei template for this vulnerability exists, and it has garnered substantial community discussion with 20 mentions, indicating active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Relevanssi | Relevanssi Premium | >= 0, <= 2.27.5CNA affecteddefault unaffected | |
| Comesio | Relevanssi – A Better Search | >= 0, <= 4.24.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.