AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15941

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects the Relevanssi plugin for WordPress, specifically through its Admin Search feature that allows users with `edit_posts` capability to execute searches. An authenticated contributor-level attacker can exploit this flaw to perform time-based blind SQL injection, potentially compromising the WordPress database. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized data access and manipulation.

CVE
CVE-2026-15941
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
WordPress

Original NVD Description

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.