
A new one-click bug discovered in the Real-Time Find and Replace plugin allows hackers to inject malicious code into sites and create fake administrator accounts. WordPress site owners are advised to update the plugin immediately to stay safe.
The bug, which is a Cross-Site Request Forgery (CSRF), can lead to Stored Cross-Site Scripting (Stored XSS) attacks. It affects all versions of Real-Time Find and Replace, up to and including 3.9.
Malicious actors can trick a legitimate website owner into injecting malicious JavaScript into their account simply by clicking on a link found in a deceptive email or comment.
The WordPress Real-Time Find and Replace plugin is particularly useful, as it allows a user to temporarily replace text or code in real time, without having to go into the website's source code and make permanent changes. The plugin is installed on over 100,000 websites.
Malicious code imports
As Chloe Chamberland, an analyst at Wordfence, states in her report , a hacker can exploit the capabilities of the plugin to insert malicious code into a site and change its content.
This JavaScript code will automatically execute “whenever a user navigates to a web page that contained the original content,” according to Chamberland.

For example, attackers could exploit the vulnerability to replace an HTML tag like <head>withtheir own malicious code. This would result in almost all pages on the compromised WordPress site being turned into a malicious tool.
The malicious code could then “be used to introduce a new administrator account, steal cookies, or redirect users to a malicious website, allowing attackers the ability to gain administrator access or infect innocent visitors browsing a compromised website,” according to the Chamberland report.
The vulnerability was discovered and reported on April 22. Wordfence rated this security flaw with CVSS 8.8, making it a high severity and it is imperative that users update to version 4.0.2, which fully fixes the bug.
