1 results (0.002 seconds)
CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1
CVE-2020-13641 – Real-Time Find and Replace <= 3.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2020-13641
27 Apr 2020 — An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser. Se detectó un problema en el plugin Real-Time Find and Replace versiones anteriores a 4.0.2 para WordPress. La función far_options_page no realizó ninguna ve... • https://wordpress.org/plugins/real-time-find-and-replace/#developers • CWE-352: Cross-Site Request Forgery (CSRF) •