CVE-2022-1472: Codesolz Better Find And Replace
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection
Affected products
- Codesolz Better Find And Replace: before 1.3.6 (fixed in 1.3.6)
Published 2022-06-20. Last modified 2026-06-17.