Vulnerabilities > Codesolz > Better Find AND Replace > 1.0.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-20 | CVE-2022-1472 | SQL Injection vulnerability in Codesolz Better Find and Replace The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection | 6.5 |
2021-10-04 | CVE-2021-24676 | Cross-site Scripting vulnerability in Codesolz Better Find and Replace The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue | 4.3 |