Real-Time Find and Replace
Real-Time Find and Replace has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2020; all 2 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Real-Time Find and Replace has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Real-Time Find and Replace is installed on roughly 70,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2020-13641Real-Time Find and Replace <= 3.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Real-Time Find and Replace
Author
Marios Alexandrou
This plugin allows you to dynamically (i.e. at the time when a page is generated) replace code and text from themes and other plugins with code and text of your choosing before a page is delivered to a user’s browser. Because the find and replace happens in real-time no changes are needed to plugins or themes which means upgrades remain easy! A pro version (a lifetime license is less than $15) with additional filtering options, setting export/import functionality, and the ability to modify admin pages is available. Here are some common uses: Want to selectively translate text that is being output by another plugin? You can do that. Trying to tweak the text on a product or shopping cart page? No problem. Hoping to remove footer text from a theme without modifying the theme? That’s easy. Here are some more examples. And some tips for those interested in on-page SEO. Remember, all of the above can be done WITHOUT modifying themes or plugin files so you’ll always be able to upgrade them without having to worry about losing custom edits.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C