HIGH
WordPress Better Find and Replace plugin <= 1.6.1 - PHP Object Injection vulnerability
Published Aug 1, 2024
8.3
HIGHCVSS 3.1
EPSS 0.40%
Description
Deserialization of Untrusted Data vulnerability in CodeSolz Better Find and Replace.This issue affects Better Find and Replace: from n/a through 1.6.1.
Affected products
-
Affected
- ≤ 1.6.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| CodeSolz | Better Find and Replace | unaffected | Affected
|
No data.
-
Affected
- ≥ 0, ≤ 1.6.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Codesolz | Better Find and Replace | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 1.6.2 or a higher version.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Aug 1, 2024
Updated Apr 28, 2026
Reserved Jun 26, 2024
Link CVE-2024-39636
CISA Vulnrichment
Updated Aug 7, 2024
Red Hat
No data
GitHub
No data