WPIntell

Source evidence

XSS Vulnerability

Better Find and Replace – AI-Powered Suggestions · support · 2025-09-23T09:23:00+00:00

mixedsentiment
highseverity
0.94relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 31 rows with source links

12.9% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

27 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
alberto.pm9 resolved
Hello there https://patchstack.com is warning about an XSS vulnerability on version 1.7.6. Could you please fix it? Thanks in advance Hi @albertopm9 , Thank you for letting us know. As far as our checks show, version 1.7.6 has no known vulnerability . The issue was in a prior release and was resolved immediately. Patchstack’s database confirms this here: https://tinyurl.com/58utxvh5 To better understand your concern, could you please share the specific details you have from Patchstack (e.g., report link, proof-of-concept, or logs) that mention version 1.7.6? That will help us verify and respond more accurately. Thanks again for helping keep everything secure. Best Regards This reply was modified 9 months, 2 weeks ago by jenneycs . Hello Sorry, but this is what I get from patchstack: https://patchstack.com/database/wordpress/plugin/real-time-auto-find-and-replace/vulnerability/wordpress-better-find-and-replace-plugin-1-7-6-cross-site-scripting-xss-vulnerability?_a_id=350 Could you fix it? Regards Hi @albertopm9 Thank you for sharing this information with us. We sincerely appreciate your diligence in reporting the matter. Please be assured that our team will address this promptly, and the fix will be incorporated in the next release, which will be deployed at the earliest possible opportunity. Best regards,

Comments

3 shown
jenneycs 2025-09-23T12:18:00+00:00

Hi @albertopm9 , Thank you for letting us know. As far as our checks show, version 1.7.6 has no known vulnerability . The issue was in a prior release and was resolved immediately. Patchstack’s database confirms this here: https://tinyurl.com/58utxvh5 To better understand your concern, could you please share the specific details you have from Patchstack (e.g., report link, proof-of-concept, or logs) that mention version 1.7.6? That will help us verify and respond more accurately. Thanks again for helping keep everything secure. Best Regards This reply was modified 9 months, 2 weeks ago by jenneycs .

alberto.pm9 2025-09-24T13:59:00+00:00

Hello Sorry, but this is what I get from patchstack: https://patchstack.com/database/wordpress/plugin/real-time-auto-find-and-replace/vulnerability/wordpress-better-find-and-replace-plugin-1-7-6-cross-site-scripting-xss-vulnerability?_a_id=350 Could you fix it? Regards

jenneycs 2025-09-24T18:15:00+00:00

Hi @albertopm9 Thank you for sharing this information with us. We sincerely appreciate your diligence in reporting the matter. Please be assured that our team will address this promptly, and the fix will be incorporated in the next release, which will be deployed at the earliest possible opportunity. Best regards,