Better Find and Replace < 1.2.9 - Reflected Cross-Site Scripting
CVE-2021-24676
6.1MEDIUM
What is CVE-2021-24676?
The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
Affected Version(s)
Better Find and Replace 1.2.9