CVE-2024-7573

Relevanssi Live Ajax Search <= 2.4 - Unauthenticated WP_Query Argument Injection

The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to insufficient validation of input supplied via POST data in the 'search' function. This makes it possible for unauthenticated attackers to inject arbitrary arguments into a WP_Query query and potentially expose sensitive information such as attachments or private posts.


We have discovered 109 live websites that are affected by CVE-2024-7573.

Run a Free Instant Scan




Affected Software

Product  Relevanssi Live Ajax Search
Category Wordpress Plugins
Vulnerable Domains109 live websites (5.39% of Relevanssi Live Ajax Search install base)
Vulnerable Versions
  • from 0 through 2.4
Vulnerable Versions Count4 versions ( 80% of all versions)


Common Weakness Enumeration

CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')



Details

  • Published - Aug 28, 2024
  • Updated - Aug 28, 2024

Credits

  • Nicola Scattaglia (finder)

Website Distribution by Country

Number of websites using CVE-2024-7573
United States31 websites



Russia11 websites
GB7 websites
France6 websites
Germany5 websites
Italy5 websites
Denmark4 websites
Israel4 websites
Spain3 websites
Finland3 websites

Website Distribution by TLD

Number of websites using CVE-2024-7573
.com33 websites
.ru9 websites
.org8 websites
.dk4 websites
.it3 websites
.net3 websites
.co.uk3 websites
.de3 websites
.fi3 websites
.cz2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-7573

Top websites that are affected by CVE-2024-7573. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States***,***
*****.*****************.it France***,***
*****************.com United States***,***
*****.org Canada***,***
****.org France***,***
******.net United States***,***
*****************.com Israel***,***
***************.***.uk GB***,***
**************.com United States***,***
*******.********.com Indonesia***,***
See full domain list

FAQ

CVE-2024-7573 is Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in Relevanssi Live Ajax Search
A total of 109 websites have been identified as vulnerable to CVE-2024-7573, based on global website indexing conducted by WebTechSurvey.
The Relevanssi Live Ajax Search is affected by the CVE-2024-7573 vulnerability.
Relevanssi Live Ajax Search versions up to and including 2.4 are vulnerable to CVE-2024-7573.