CVE-2026-15941: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Relevanssi Relevanssi Premium – A Better Search
CVE-2026-15941 is a medium severity SQL injection vulnerability in the Relevanssi Premium WordPress plugin. It affects the Admin Search page where authenticated users with the edit_posts capability can perform searches. The vulnerability arises because user-controlled taxonomy query data is sanitized as text but not properly parameterized before being used in an SQL query. This allows an authenticated contributor-level attacker to perform time-based blind SQL injection against the WordPress database via an AJAX request.
AI Analysis
Technical Summary
The Relevanssi Premium plugin's Admin Search AJAX handler accepts a URL-encoded args parameter that is parsed into a WP_Query. User-controlled taxonomy values are sanitized as text but directly interpolated into a term taxonomy lookup SQL query without parameterization. This improper neutralization of special elements in SQL commands (CWE-89) enables authenticated users with edit_posts capability to inject SQL commands, leading to time-based blind SQL injection attacks against the WordPress database.
Potential Impact
An attacker with contributor-level privileges can exploit this vulnerability to perform time-based blind SQL injection, potentially allowing them to extract sensitive information from the WordPress database. The vulnerability does not impact integrity or availability directly but compromises confidentiality by exposing data through SQL injection.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict contributor-level access and avoid using the Admin Search feature for untrusted users. Monitor for updates from the Relevanssi vendor regarding patches or official mitigations.
CVE-2026-15941: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Relevanssi Relevanssi Premium – A Better Search
Description
CVE-2026-15941 is a medium severity SQL injection vulnerability in the Relevanssi Premium WordPress plugin. It affects the Admin Search page where authenticated users with the edit_posts capability can perform searches. The vulnerability arises because user-controlled taxonomy query data is sanitized as text but not properly parameterized before being used in an SQL query. This allows an authenticated contributor-level attacker to perform time-based blind SQL injection against the WordPress database via an AJAX request.
CVSS v3.1
Score 6.5medium
Affected software
Relevanssi
Relevanssi Premium – A Better Search
comesio
Relevanssi – A Better Search
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Relevanssi Premium plugin's Admin Search AJAX handler accepts a URL-encoded args parameter that is parsed into a WP_Query. User-controlled taxonomy values are sanitized as text but directly interpolated into a term taxonomy lookup SQL query without parameterization. This improper neutralization of special elements in SQL commands (CWE-89) enables authenticated users with edit_posts capability to inject SQL commands, leading to time-based blind SQL injection attacks against the WordPress database.
Potential Impact
An attacker with contributor-level privileges can exploit this vulnerability to perform time-based blind SQL injection, potentially allowing them to extract sensitive information from the WordPress database. The vulnerability does not impact integrity or availability directly but compromises confidentiality by exposing data through SQL injection.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict contributor-level access and avoid using the Admin Search feature for untrusted users. Monitor for updates from the Relevanssi vendor regarding patches or official mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-16T08:59:41.548Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a72cd1bbf8831d5394f407c
Added to database: 08/05/2026, 05:41:47 UTC
Last enriched: 08/12/2026, 15:28:03 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.