PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97641 comesio CVE debrief

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Vendor
comesio
Product
Relevanssi – A Better Search
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-02
Original CVE updated
2026-10-03
Advisory published
2026-10-02
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations with the Relevanssi – A Better Search plugin should assess exposure and verify the configuration of the 'Allowable tags in excerpts' setting.

Why it matters

CVE-2026-97641 is a Stored Cross-Site Scripting vulnerability in the Relevanssi – A Better Search plugin for WordPress. Defenders should prioritize verifying the configuration of the 'Allowable tags in excerpts' setting and ensuring that input sanitization and output escaping are properly implemented to prevent potential exploitation.

  • Unauthenticated attackers could inject arbitrary web scripts
  • Injected scripts could execute on page access
  • Defenders must verify 'Allowable tags in excerpts' setting configuration
  • Input sanitization and output escaping must be properly implemented

Technical summary

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3. This is due to insufficient input sanitization and output escaping. An attacker could inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the administrator has configured a non-empty value for the 'Allowable tags in excerpts' setting, such as the default example value of <p><a><strong>.

Defensive priority

Defenders should prioritize verifying the configuration of the 'Allowable tags in excerpts' setting and ensuring that input sanitization and output escaping are properly implemented.

Recommended defensive actions

  • Verify the configuration of the 'Allowable tags in excerpts' setting
  • Ensure that input sanitization and output escaping are properly implemented
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. The vulnerability is a Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 4.28.3 of the Relevanssi – A Better Search plugin for WordPress. The CVE record was published on 2026-10-02T08:17:05.837Z and has not been modified since then. The NVD entry provides additional information on the vulnerability, including its CVSS score and affected versions. Defenders should verify '

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97641 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97641

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97641 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97641

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.