CVE-2020-13641
Summary
| CVE | CVE-2020-13641 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-28 04:15:00 UTC |
| Updated | 2020-05-28 20:00:00 UTC |
| Description | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Infolific | Real-time Find And Replace | All | All | All | All |
| Application | Infolific | Real-time Find And Replace | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Real-Time Find and Replace – WordPress plugin | WordPress.org | MISC | wordpress.org | Release Notes, Third Party Advisory |
| High Severity Vulnerability Patched in Real-Time Find and Replace Plugin | MISC | www.wordfence.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.