Extension WordPress
Vulnérabilités Better Find and Replace – AI-Powered Suggestions
Cette page rassemble les failles publiées pour Better Find and Replace – AI-Powered Suggestions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Better Find and Replace – AI-Powered Suggestions
8 fiches
Better Find and Replace – AI-Powered Suggestions <= 1.7.9 – Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes…
*-1.7.9
1.8.0
16/04/2026
Better Find and Replace <= 1.7.7 – Authenticated (Subscriber+) Limited Code Injection
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function.…
*-1.7.7
1.7.8
07/11/2025
Better Find and Replace <= 1.7.7 – Missing Authorization
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to a missing capability check on the rtafar_ajax() function in all versions up to, and including, 1.7.7. This makes it…
*-1.7.7
1.7.8
05/11/2025
Better Find and Replace <= 1.7.6 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Better Find and Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
*-1.7.6
1.7.7
22/09/2025
Better Find and Replace <= 1.6.7 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The Better Find and Replace plugin for WordPress is vulnerable to unauthorized Privilege Escalation due to a missing capability check on the db_string_replace() function in all versions up to, and including, 1.6.7. This makes it possible for authenticated…
*-1.6.7
1.6.8
27/01/2025
Better Find and Replace <= 1.6.1 – Unauthenticated PHP Object Injection
The Better Find and Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.1 via deserialization of untrusted input from the 'str' parameter. This makes it possible for unauthenticated attackers…
*-1.6.1
1.6.2
29/07/2024
Better Find and Replace <= 1.3.5 – Admin+ SQL Injection
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
[*, 1.3.6)
1.3.6
30/05/2022
Better Find and Replace <= 1.2.8 – Reflected Cross-Site Scripting
The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
*-1.2.8
1.2.9
06/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.