Vulnerability in Real-Time Find and Replace Plugin for WordPress
CVE-2020-13641
8.8HIGH
What is CVE-2020-13641?
A vulnerability was discovered in the Real-Time Find and Replace plugin for WordPress, affecting versions prior to 4.0.2. The issue lies in the far_options_page function, which fails to implement proper nonce verification. This oversight allows attackers to forge requests on behalf of an administrator. As a result, malicious JavaScript can be injected into find and replace rules, posing a risk as this code may execute in the browser of an unsuspecting victim. Users of this plugin should ensure they are updated to the latest version to mitigate this vulnerability.