Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title
medium
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access...
- CVSS:
- 5.4
- Affected:
- up to 1.7.9
- Fixed in:
- 1.8.0
- Disclosed:
- Apr 15, 2026
CVE-2026-3369 on NVD →
Better Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code Injection
high
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-l...
- CVSS:
- 8.8
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Nov 7, 2025
CVE-2025-9334 on NVD →
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.7.8
unknown
[en] The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger...
- Affected:
- up to 1.7.8
- Fixed in:
- 1.7.8
- Disclosed:
- Nov 6, 2025
CVE-2025-12360 on NVD →
Better Find and Replace <= 1.7.7 - Missing Authorization
medium
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it possible for authenticated attackers, with Subscriber-level access, to trigger Open...
- CVSS:
- 4.3
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.8
- Disclosed:
- Nov 5, 2025
CVE-2025-12360 on NVD →
Better Find and Replace <= 1.7.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Better Find and Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts...
- CVSS:
- 4.4
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Sep 22, 2025
CVE-2025-53466 on NVD →
Better Find and Replace <= 1.6.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
high
The Better Find and Replace plugin for WordPress is vulnerable to unauthorized Privilege Escalation due to a missing capability check on the db_string_replace() function in all versions up to, and including, 1.6.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to replace va...
- CVSS:
- 8.8
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Jan 27, 2025
CVE-2025-24734 on NVD →
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.6.8
unknown
[en] Missing Authorization vulnerability in CodeSolz Better Find and Replace allows Privilege Escalation. This issue affects Better Find and Replace: from n/a through 1.6.7.
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Jan 27, 2025
CVE-2025-24734 on NVD →
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.6.2
unknown
[en] Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- Aug 1, 2024
CVE-2024-39636 on NVD →
Better Find and Replace <= 1.6.1 - Unauthenticated PHP Object Injection
high
The Better Find and Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.1 via deserialization of untrusted input from the 'str' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 8.3
- Affected:
- up to 1.6.1
- Fixed in:
- 1.6.2
- Disclosed:
- Jul 29, 2024
CVE-2024-39636 on NVD →
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.3.6
unknown
[en] The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jun 20, 2022
CVE-2022-1472 on NVD →
Better Find and Replace <= 1.3.5 - Admin+ SQL Injection
high
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
- CVSS:
- 7.2
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- May 30, 2022
CVE-2022-1472 on NVD →
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] <= 1.3.4
unknown
SQL Injection (SQLi) vulnerability discovered in WordPress Better Find and Replace plugin (versions <= 1.3.4).
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- May 2, 2022
Better Find and Replace – AI-Powered Suggestions [real-time-auto-find-and-replace] < 1.2.9
unknown
[en] The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Oct 4, 2021
CVE-2021-24676 on NVD →
Better Find and Replace <= 1.2.8 - Reflected Cross-Site Scripting
medium
The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- Sep 6, 2021
CVE-2021-24676 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database