Unauthorized API Access in Better Find and Replace Plugin for WordPress
CVE-2025-12360
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-12360?
The Better Find and Replace – AI-Powered Suggestions plugin for WordPress has a vulnerability that allows authenticated users with Subscriber-level access to bypass capability checks. This flaw in the rtafar_ajax() function can enable these attackers to exploit the OpenAI API key, leading to unintended quota consumption that could incur unexpected costs.
Affected Version(s)
Better Find and Replace – AI-Powered Suggestions * <= 1.7.7