plugin

Real Time Auto Find And Replace Vulnerabilities

14 known security issues reported for the Real Time Auto Find And Replace WordPress plugin. Most recent disclosed Apr 15, 2026.

4 high 4 medium

Running Real Time Auto Find And Replace on your site? Check whether your installed version is affected.

Scan your site free

Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title

medium

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access...

CVSS:
5.4
Affected:
up to 1.7.9
Fixed in:
1.8.0
Disclosed:
Apr 15, 2026

CVE-2026-3369 on NVD →

Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection

high

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-l...

CVSS:
8.8
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Nov 7, 2025

CVE-2025-9334 on NVD →

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.7.8

unknown

[en] The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger...

Affected:
up to 1.7.8
Fixed in:
1.7.8
Disclosed:
Nov 6, 2025

CVE-2025-12360 on NVD →

Better Find and Replace <= 1.7.7 - Missing Authorization

medium

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger Open...

CVSS:
4.3
Affected:
up to 1.7.7
Fixed in:
1.7.8
Disclosed:
Nov 5, 2025

CVE-2025-12360 on NVD →

Better Find and Replace <= 1.7.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Better Find and Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts...

CVSS:
4.4
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Sep 22, 2025

CVE-2025-53466 on NVD →

Better Find and Replace <= 1.6.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

high

The Better Find and Replace plugin for WordPress is vulnerable to unauthorized Privilege Escalation due to a missing capability check on the db_string_replace() function in all versions up to, and including, 1.6.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to replace va...

CVSS:
8.8
Affected:
up to 1.6.7
Fixed in:
1.6.8
Disclosed:
Jan 27, 2025

CVE-2025-24734 on NVD →

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.6.8

unknown

[en] Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege Escalation. This issue affects Better Find and Replace: from n/a through 1.6.7.

Affected:
up to 1.6.8
Fixed in:
1.6.8
Disclosed:
Jan 27, 2025

CVE-2025-24734 on NVD →

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.6.2

unknown

[en] Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Aug 1, 2024

CVE-2024-39636 on NVD →

Better Find and Replace <= 1.6.1 - Unauthenticated PHP Object Injection

high

The Better Find and Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.1 via deserialization of untrusted input from the 'str' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
8.3
Affected:
up to 1.6.1
Fixed in:
1.6.2
Disclosed:
Jul 29, 2024

CVE-2024-39636 on NVD →

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.3.6

unknown

[en] The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Jun 20, 2022

CVE-2022-1472 on NVD →

Better Find and Replace <= 1.3.5 - Admin+ SQL Injection

high

The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

CVSS:
7.2
Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
May 30, 2022

CVE-2022-1472 on NVD →

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] <= 1.3.4

unknown

SQL Injection (SQLi) vulnerability discovered in WordPress Better Find and Replace plugin (versions <= 1.3.4).

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
May 2, 2022

Better Find and Replace &#8211; AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.2.9

unknown

[en] The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Oct 4, 2021

CVE-2021-24676 on NVD →

Better Find and Replace <= 1.2.8 - Reflected Cross-Site Scripting

medium

The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.2.8
Fixed in:
1.2.9
Disclosed:
Sep 6, 2021

CVE-2021-24676 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database