First published: Mon Oct 04 2021(Updated: )
The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Codesolz Better Find and Replace | <1.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24676 has a medium severity rating due to its ability to lead to a reflected Cross-Site Scripting vulnerability.
To fix CVE-2021-24676, update the Better Find and Replace plugin to version 1.2.9 or higher.
CVE-2021-24676 is classified as a reflected Cross-Site Scripting vulnerability.
CVE-2021-24676 affects all versions of the Better Find and Replace plugin prior to 1.2.9.
CVE-2021-24676 can be exploited on the All Masking Rules page of the Better Find and Replace plugin.