CVE-2024-1380: Relevanssi – A Better Search <= 4.22.0 (Free) and <= 2.25.0 (Premium) - Missing Authorization to Unauthenticated Query Log Export
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the relevanssiexportlogcheck() function in all versions up to, and including, 4.22.0 (Free) and 2.25.0 (Premium). This makes it possible for unauthenticated attackers to export the query log data. The vendor has indicated that they may look into adding a capability check for proper authorization control, however, this vulnerability is theoretically patched as is.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1380?
CVE-2024-1380 has a medium severity rating due to its potential for unauthorized data access.
How do I fix CVE-2024-1380?
To fix CVE-2024-1380, update the Relevanssi plugin to version 4.22.1 or later.
Who is affected by CVE-2024-1380?
CVE-2024-1380 affects all versions of the Relevanssi plugin for WordPress up to and including version 4.22.0.
What type of vulnerability is CVE-2024-1380?
CVE-2024-1380 is a security vulnerability that allows unauthorized access due to a missing capability check.
Can CVE-2024-1380 lead to data breaches?
Yes, CVE-2024-1380 can potentially lead to data breaches by allowing unauthenticated attackers to export sensitive query logs.