Security Advisory

CVE-2022-3850

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-28 13:47:12
Last updated 2025-04-25 15:00:33
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack