CVE-2024-7573: Relevanssi Live Ajax Search <= 2.4 - Unauthenticated WP_Query Argument Injection
The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to insufficient validation of input supplied via POST data in the 'search' function. This makes it possible for unauthenticated attackers to inject arbitrary arguments into a WPQuery query and potentially expose sensitive information such as attachments or private posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7573?
CVE-2024-7573 is classified as a high severity vulnerability due to its potential for argument injection attacks.
How do I fix CVE-2024-7573?
To fix CVE-2024-7573, update the Relevanssi Live Ajax Search plugin to version 2.5 or higher.
Who is affected by CVE-2024-7573?
CVE-2024-7573 affects all versions of the Relevanssi Live Ajax Search plugin up to and including 2.4.
Can unauthenticated users exploit CVE-2024-7573?
Yes, unauthenticated attackers can exploit CVE-2024-7573 due to insufficient input validation.
What type of vulnerability is CVE-2024-7573?
CVE-2024-7573 is an argument injection vulnerability found in the Relevanssi Live Ajax Search plugin.