MEDIUM
comesio
CVE published 2026-09-11
CVE-2026-19985
The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages that execute if they can trick a user into performing an action such as clicking on a specially crafted link. The vulnerability is due to insufficient input sanitization [truncated]