Description
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-04-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The reported vulnerability resides in the image title field of the Better Find and Replace – AI‑Powered Suggestions WordPress plugin. Due to inadequate input sanitization and lack of output escaping, attackers who have author‑level or higher privileges can inject arbitrary scripts into the title of an uploaded image. When a user later views a page containing that image, the injected scripts are executed in the context of the site, allowing the attacker to run malicious code on the victim's browser. The flaw aligns with CWE‑79, which signifies an XSS weakness.

Affected Systems

This issue affects the Better Find and Replace – AI‑Powered Suggestions plugin published by Codesolz. All WordPress sites running a vulnerable version of the plugin, from the original release up to and including 1.7.9, are potentially exposed. Sites that have upgraded to a newer release are not impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation evidence is limited. Nonetheless, the flaw requires only an authenticated author or higher account, a role commonly granted to content editors, making the attack vector readily achievable through legitimate plugin usage. The absence of a publicly released exploit does not reduce the need for remediation, as the stored XSS can be leveraged to compromise site visitors.

Generated by OpenCVE AI on April 17, 2026 at 03:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Better Find and Replace – AI‑Powered Suggestions plugin to the latest version (≥1.8.0) which contains the input sanitization fix.
  • If an upgrade is not possible immediately, manually remove or sanitize any image titles that contain suspicious characters by using the plugin’s edit interface or a database query that strips tags from the image_title field.
  • Disable the image title functionality or the entire plugin until the upgrade is applied, ensuring no further XSS vectors remain active.

Generated by OpenCVE AI on April 17, 2026 at 03:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Apr 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Codesolz
Codesolz better Find And Replace – Ai-powered Suggestions
Wordpress
Wordpress wordpress
Vendors & Products Codesolz
Codesolz better Find And Replace – Ai-powered Suggestions
Wordpress
Wordpress wordpress

Thu, 16 Apr 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, and including, 1.7.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Better Find and Replace – AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Codesolz Better Find And Replace – Ai-powered Suggestions
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-16T14:04:23.811Z

Reserved: 2026-02-27T21:16:05.738Z

Link: CVE-2026-3369

cve-icon Vulnrichment

Updated: 2026-04-16T14:04:19.194Z

cve-icon NVD

Status : Received

Published: 2026-04-16T12:16:08.233

Modified: 2026-04-16T12:16:08.233

Link: CVE-2026-3369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T03:30:08Z

Weaknesses