Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress <= 1.5.2 - Reflected Cross-Site Scripting via Pricing Page Query Parameters

Medium 6.1 CWE-79Fixed in 1.5.3
ID
WPSEC-2026-0761
Plugin
Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links (update-urls)
Affected
all versions before 1.5.3
Remediation
Update to 1.5.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-11
Attack surface
Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress on WPSec AttackSurface
Fix released
Published

Description

The Search & Replace Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via query string parameters on the pricing page of the bundled Freemius SDK in all versions up to, and including, 1.5.2. This is due to the page merging arbitrary $_GET parameters over the trusted configuration values it passes to the pricing app, such as contact_url, fs_wp_endpoint_url, request_handler_url, plugin_id and license, without validating them. This makes it possible for unauthenticated attackers to control the pricing app's configuration, for example by setting a javascript: URL as the contact link or by pointing the app's requests at an attacker-controlled endpoint, and so inject arbitrary web scripts if they can trick an administrator into opening a crafted link and interacting with the page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0