Stored Cross-Site Scripting Vulnerability in Better Find and Replace Plugin for WordPress
CVE-2026-3369
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2026-3369?
The Better Find and Replace β AI-Powered Suggestions plugin for WordPress has a vulnerability that allows authenticated attackers with author-level access or higher to exploit the insufficient input sanitization and output escaping. This risk is particularly serious as attackers can inject malicious scripts via the uploaded image titles. When a user accesses a page affected by such an injection, arbitrary scripts may execute, potentially compromising user data and site integrity.
Affected Version(s)
Better Find and Replace β AI-Powered Suggestions 0 <= 1.7.9