WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Relevanssi – A Better Search

Relevanssi replaces the default search with a partial-match search that sorts results by relevance. It also indexes comments and shortcode content.

14Reported vulnerabilities
9.8Highest CVSS score
4.28.2Latest version
100,000+Active installs

What to do now

Update Relevanssi – A Better Search to 4.27.2 or later. 14 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-1380 Medium 5.3 50.2% Before 4.22.1 4.22.1 March 13, 2024
CVE-2017-1000038 Medium 6.1 1.1% 3.5.7.1 to 3.5.7.1 (inclusive) 3.5.8 July 17, 2017
CVE-2024-3214 Critical 9.8 0.8% Before 4.22.2 4.22.2 April 9, 2024
CVE-2018-9034 Medium 5.4 1.9% 4.0.4 and earlier 4.0.5 April 4, 2018
WF-4b8d057b-1909-46d4-8e0a-d5c7c9f7001c Critical 9.8 3.3 and earlier 3.3.1 February 25, 2014
CVE-2023-7199 Medium 5.3 0.6% 2.25.0 and earlier 2.25.0 January 29, 2024
WF-69fd1068-4bbd-4e8a-9d35-5e9a072c72e1 High 8.7 Before 3.6.1 3.6.1 April 10, 2018
CVE-2025-4396 High 7.5 2.7% 0 to 2.27.5 (inclusive)
0 to 4.24.4 (inclusive)
2.27.6 May 13, 2025
CVE-2024-3213 High 8.2 0.8% Before 4.22.2 4.22.2 April 9, 2024
CVE-2024-7630 High 7.5 0.5% Before 4.23.0 4.23.0 August 16, 2024
CVE-2026-15941 Medium 6.5 0.2% 0 to 2.30.2 (inclusive)
0 to 4.27.1 (inclusive)
4.27.2 August 5, 2026
CVE-2025-4054 Medium 6.1 0.4% 0 to 2.27.4 (inclusive)
0 to 4.24.3 (inclusive)
2.27.5 May 7, 2025
CVE-2014-9443 Medium 4.3 1.6% 3.3.7.1 to 3.3.7.1 (inclusive) 3.3.8 January 2, 2015
CVE-2025-5016 Medium 4.7 0.2% 0 to 2.27.6 (inclusive)
0 to 4.24.5 (inclusive)
2.27.7 May 31, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.