{"error":0,"message":null,"data":{"name":"Real-Time Find and Replace","plugin":"real-time-find-and-replace","link":"https:\/\/wordpress.org\/plugins\/real-time-find-and-replace\/","latest":"1787188140","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"79151ff612bd379fe457fdc53b625c89b05a8cb361e7c47ab886da7b568c2926","name":"Real-Time Find and Replace [real-time-find-and-replace] < 4.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-13641","name":"CVE-2020-13641","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-13641","description":"[en] An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.","date":"2020-05-28"},{"id":"ed0b228bf345bcbc9ef1a3c810e98e25330fe55a","name":"WordPress Real-Time Find and Replace plugin <= 3.9 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/real-time-find-and-replace\/vulnerability\/wordpress-real-time-find-and-replace-plugin-3-9-cross-site-request-forgery-csrf-vulnerability-leading-to-stored-cross-site-scripting-xss","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by WordFence in WordPress Real-Time Find and Replace plugin (versions <= 3.9).","date":"2020-04-27"},{"id":"c1a7fa87ce817c1bce55e0f9013798d3806f7d20","name":"Real-Time Find and Replace <= 3.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/real-time-find-and-replace\/real-time-find-and-replace-39-cross-site-request-forgery-to-stored-cross-site-scripting","description":"An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.","date":"2020-04-27"},{"id":"92a30d3d-3afe-4a34-828f-ad0c7454c02a","name":"Real-Time Find and Replace &lt; 4.0.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/92a30d3d-3afe-4a34-828f-ad0c7454c02a","description":"This flaw could allow any user to inject malicious Javascript anywhere on a site if they could trick a site&rsquo;s administrator into performing an action, like clicking on a link in a comment or email.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"fd9d44f4bc0daa7e94361d8dc181daab63f267c3a90e9fab19c2807bfd3a8ee4","name":"Real-Time Find and Replace [real-time-find-and-replace] < 3.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"499204d919883f9a0b11921c6814e53878923a63","name":"Real-Time Find and Replace <= 3.8 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/real-time-find-and-replace\/real-time-find-and-replace-38-cross-site-scripting","description":"The Real-Time Find and Replace plugin for WordPress is vulnerable to Cross-Site Scripting via the \u2018REQUEST_URI\u2019 parameter in versions before 3.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2017-04-14"}],"impact":[]},{"uuid":"7f8e5a4052c32decf8c109d94a482c1856298e41a7c277869e4db38f27b48920","name":"Real-Time Find and Replace [real-time-find-and-replace] < 3.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"abe66334-3eee-493b-b673-f5db18e01052","name":"Real Time Find and Replace &lt;= 3.8 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/abe66334-3eee-493b-b673-f5db18e01052","description":"The Real-Time Find and Replace WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]}]},"updated":"1776563733"}