What is CVE-2026-15941?
CVE-2026-15941 allows users with `edit_posts` capability in WordPress to inject user-controlled taxonomy query data into the `WP_Query` via the `args` parameter in the AJAX handler of the Relevanssi plugin's Admin Search page. This could lead to unauthorized data exposure through manipulated queries. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15941, WordPress dashboard-da `edit_posts` icazəsi olan istifadəçilərin Relevanssi plugin-inin Admin Search səhifəsi vasitəsilə AJAX handler-ə ötürülən `args` parametri ilə `WP_Query` sorğularını manipulyasiya etməsinə imkan verir. Bu, istifadəçiyə öz idarə etdiyi taksonomiya sorğu məlumatlarını (user-controlled taxonomy query data) ötürərək icazəsiz məlumat əldə etməsinə səbəb ola bilər. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What is the minimum user capability required to exploit CVE-2026-15941 in WordPress?
The vulnerability can be exploited by any user with the `edit_posts` capability.
Which parameter in the Relevanssi plugin is used to exploit CVE-2026-15941?
The `args` parameter passed to the AJAX handler is used to inject the malicious WP_Query data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.