---
id: CVE-2025-9334
title: >-
  The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is
  vulnerable to Limited Code Injection in all versions up to, and including,
  1.7.7
summary: >-
  The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is
  vulnerable to Limited Code Injection in all versions up to, and including,
  1.7.7. This is due to insufficient input validation and restriction on the
  'rtafar_aj…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2025-11-08'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9334'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/real-time-auto-find-and-replace/trunk/core/actions/RTAFAR_CustomAjax.php#L29
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/real-time-auto-find-and-replace/trunk/core/admin/functions/DbReplacer.php#L507
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/real-time-auto-find-and-replace/trunk/core/lib/Util.php#L233
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3389979/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/232f3a15-3bd3-44fa-aa07-f055e8fcda88?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00503
epssPercentile: 0.40743
ingestedAt: '2026-09-30T23:29:32.464Z'
---

## Overview

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all versions up to, and including, 1.7.7. This is due to insufficient input validation and restriction on the 'rtafar_ajax' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to call arbitrary plugin functions and execute code within those functions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
