A critical vulnerability, CVE-2025-4396, has been discovered in the Relevanssi – A Better Search plugin for WordPress, affecting all versions up to 4.24.4 (Free) and 2.27.4 (Premium). This flaw stems from insufficient input sanitization and improper SQL query preparation in handling the query parameters, enabling unauthenticated attackers to perform time-based SQL Injection. By exploiting this vulnerability, threat actors can append malicious SQL statements to existing queries, allowing them to extract sensitive data from the underlying WordPress database. Users are strongly advised to update the plugin to a patched version. The IONIX research team confirmed the impact through controlled exploit validation, as detailed in this post.
References:

