{
 "id": "WPSEC-2026-0761",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0761/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0761/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0761/index.md",
 "title": "Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress <= 1.5.2 - Reflected Cross-Site Scripting via Pricing Page Query Parameters",
 "description": "The Search & Replace Everything plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via query string parameters on the pricing page of the bundled Freemius SDK in all versions up to, and including, 1.5.2. This is due to the page merging arbitrary $_GET parameters over the trusted configuration values it passes to the pricing app, such as contact_url, fs_wp_endpoint_url, request_handler_url, plugin_id and license, without validating them. This makes it possible for unauthenticated attackers to control the pricing app's configuration, for example by setting a javascript: URL as the contact link or by pointing the app's requests at an attacker-controlled endpoint, and so inject arbitrary web scripts if they can trick an administrator into opening a crafted link and interacting with the page.",
 "plugin": {
  "slug": "update-urls",
  "name": "Update URLs – Quick and Easy way to search old links and replace them with new links in WordPress",
  "full_name": "Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links",
  "wordpress_org": "https://wordpress.org/plugins/update-urls/",
  "advisories_url": "https://wpsec.com/vuln/plugin/update-urls/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/update-urls"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.5.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.5.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.5.3",
 "remediation": "Update to 1.5.3 or later.",
 "fix_released": "2026-10-10T08:38:34+00:00",
 "published": "2026-10-11T08:41:09+00:00",
 "updated": "2026-10-10T14:53:57.069876+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0761/",
  "https://plugins.svn.wordpress.org/update-urls/tags/1.5.3/",
  "https://wordpress.org/plugins/update-urls/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/update-urls",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-11"
 }
}