Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress <= 1.5.2 - Reflected Cross-Site Scripting via Pricing Page Query Parameters
- ID
- WPSEC-2026-0761
- Plugin
- Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links (update-urls)
- Affected
- all versions before 1.5.3
- Remediation
- Update to 1.5.3 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-11
- Attack surface
- Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress on WPSec AttackSurface
- Fix released
- Published
Description
The Search & Replace Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via query string parameters on the pricing page of the bundled Freemius SDK in all versions up to, and including, 1.5.2. This is due to the page merging arbitrary $_GET parameters over the trusted configuration values it passes to the pricing app, such as contact_url, fs_wp_endpoint_url, request_handler_url, plugin_id and license, without validating them. This makes it possible for unauthenticated attackers to control the pricing app's configuration, for example by setting a javascript: URL as the contact link or by pointing the app's requests at an attacker-controlled endpoint, and so inject arbitrary web scripts if they can trick an administrator into opening a crafted link and interacting with the page.
References
- https://wpsec.com/vuln/WPSEC-2026-0761/
- https://plugins.svn.wordpress.org/update-urls/tags/1.5.3/
- https://wordpress.org/plugins/update-urls/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS