CVE-2024-3213: Relevanssi – A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update
The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the relevanssiupdatecounts() function in all versions up to, and including, 4.22.1. This makes it possible for unauthenticated attackers to execute expensive queries on the application that could lead into DOS.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3213?
CVE-2024-3213 has a high severity due to the potential for unauthorized modification of data by unauthenticated attackers.
How do I fix CVE-2024-3213?
To mitigate CVE-2024-3213, update the Relevanssi – A Better Search plugin to version 4.22.2 or later.
What versions of Relevanssi are affected by CVE-2024-3213?
CVE-2024-3213 affects all versions of the Relevanssi – A Better Search plugin up to and including version 4.22.1.
What kind of attack is possible with CVE-2024-3213?
CVE-2024-3213 allows unauthenticated attackers to execute potentially expensive database operations due to missing capability checks.
Is CVE-2024-3213 a local or remote vulnerability?
CVE-2024-3213 is a remote vulnerability that can be exploited without local access to the affected WordPress site.