Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 09 Jun 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Relevanssi
Relevanssi relevanssi |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:relevanssi:relevanssi:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Relevanssi
Relevanssi relevanssi |
Wed, 09 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mikkosaari
Mikkosaari relevanssi |
|
| CPEs | cpe:2.3:a:mikkosaari:relevanssi:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mikkosaari
Mikkosaari relevanssi |
|
| Metrics |
cvssV3_1
|
Tue, 08 Oct 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of the Contributor+ by embedding malicious script, which entails account takeover backdoor | |
| Title | Relevanssi < 4.23.1 - Contributor+ Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-09T15:20:50.596Z
Reserved: 2024-09-19T20:42:11.101Z
Link: CVE-2024-9021
Updated: 2024-10-09T15:20:46.094Z
Status : Analyzed
Published: 2024-10-08T06:15:02.693
Modified: 2025-06-09T21:30:03.113
Link: CVE-2024-9021
No data.
OpenCVE Enrichment
No data.