CVE-2026-3369 is a Stored Cross-Site Scripting (XSS) vulnerability in the Better Find and Replace – AI-Powered Suggestions WordPress plugin affecting versions up to and including 1.7.9. The vulnerability stems from insufficient input sanitization and output escaping of image title fields, allowing authenticated attackers with author-level privileges or higher to inject malicious scripts into pages. When users access these compromised pages, the injected scripts execute in their browsers. The vulnerability carries a CVSS score of 5.4 (MEDIUM severity) with a network-based attack vector requiring low complexity and low privilege requirements, though user interaction is necessary for exploitation. The attack has limited scope, with impacts confined to low-level confidentiality and integrity compromise, and no availability impact. The EPSS score of 0.0001 indicates minimal probability of exploitation in the wild relative to other known vulnerabilities. There is no evidence of active exploitation in the wild, with the vulnerability absent from known exploit databases and community threat lists. The KEV (Known Exploited Vulnerability) designation is negative, and the threat remains on the inactive hot list, suggesting limited real-world attention or weaponization. Organizations running affected plugin versions should prioritize updating to patched releases, particularly in environments where author-level WordPress users may be untrusted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Codesolz | Better Find And Replace – AI-Powered Suggestions | >= 0, <= 1.7.9CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.