← WordPress Vulnerabilities
WordPress security by component

Relevanssi Light

Relevanssi Light is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: relevanssi-light

CVE-2026-59533: Relevanssi Light permits unauthenticated SQL injection

Relevanssi Light through 1.2.2 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user. The Patchstack CNA record does not disclose the endpoint, action, parameter, query or vulnerable function.

PublishedJul 27, 2026
Known safe version1.2.3
Safe version
Jul 27, 2026 CVE-2026-59533
Relevanssi Light permits unauthenticated SQL injection
Relevanssi Light through 1.2.2 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user. The Patchstack CNA record does not disclose the endpoint, action, parameter, query or vulnerable function.
1.2.3
CVE9.3
NVDPending