Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Find_and_replace_all
(Find_and_replace_all_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2022-11-28 | CVE-2022-2311 | The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue. | Find_and_replace_all | 6.1 | ||
2022-11-28 | CVE-2022-3850 | The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack | Find_and_replace_all | 4.3 |