What the vulnerability does
01Description
Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affects Better Find and Replace: from n/a through <= 1.6.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Missing Authorization vulnerability in CodeSolz Better Find and Replace real-time-auto-find-and-replace allows Privilege Escalation.This issue affects Better Find and Replace: from n/a through <= 1.6.7.
Explanation of Vulnerability in Simple Terms
Better Find and Replace versions 1.6.7 and earlier lack proper authorization checks, allowing authenticated users with low privileges to read, modify, or delete data they should not access. An attacker with a basic user account can perform administrative actions without restriction. This affects all data confidentiality, integrity, and availability on sites running the vulnerable plugin.
What an attacker can do
Read, modify, or delete any site data without proper permission checks.
Potential impact on your site
Any authenticated user can access and alter sensitive content, user data, or site configuration.
Conditions required to exploit
Attacker needs a low-privilege user account on the site; no special interaction required.
Key dates
External resources
Related vulnerabilities