CVE-2020-13641
Real-Time Find and Replace <= 3.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.
Se detectó un problema en el plugin Real-Time Find and Replace versiones anteriores a 4.0.2 para WordPress. La función far_options_page no realizó ninguna verificación de nonce, permitiendo que las peticiones sean falsificadas en nombre de un administrador. Las reglas de encontrar y remplazar podrían ser actualizadas con JavaScript malicioso, permitiendo que sea ejecutada más tarde en el navegador de las víctimas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-27 CVE Published
- 2020-05-27 CVE Reserved
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/real-time-find-and-replace/#developers | Release Notes |
URL | Date | SRC |
---|---|---|
https://www.wordfence.com/blog/2020/04/high-severity-vulnerability-patched-in-real-time-find-and-replace-plugin | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Infolific Search vendor "Infolific" | Real-time Find And Replace Search vendor "Infolific" for product "Real-time Find And Replace" | < 4.0.2 Search vendor "Infolific" for product "Real-time Find And Replace" and version " < 4.0.2" | wordpress |
Affected
|