Impact
CodeSolz’s Better Find and Replace real‑time‑auto‑find‑and‑replace plugin contains a Missing Authorization flaw (CWE‑862). Based on the description, it is inferred that a user with limited permissions can manipulate the replacement feature to execute actions or elements that should be restricted to administrators, effectively raising the attacker’s privileges within the WordPress installation.
Affected Systems
The vulnerability is present in all releases of the Better Find and Replace plugin up to and including version 1.6.7. It affects sites that have installed the plugin from the WordPress repository or via the vendor CodeSolz.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity. Although the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, the plugin’s functionality is exposed through the web interface, making it potentially exploitable by anyone with a valid WordPress account or by an attacker who can gain access to a site’s content. Based on the description, it is inferred that the lack of proper authorization checks allows privilege escalation without needing additional credentials beyond those already held by a permitted user.
OpenCVE Enrichment
EUVD