PT-2024-15128 · WordPress · Better Search Replace

Mopman

+1

·

Published

2024-01-25

·

Updated

2025-09-24

·

CVE-2023-6933

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Better Search Replace plugin for WordPress versions up to, and including, 1.4.4
Description The issue is related to PHP Object Injection via deserialization of untrusted input, allowing unauthenticated attackers to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Approximately 1 million sites are impacted. Over 2,500 attacks targeting this issue have been reported in the past 24 hours.
Recommendations For versions up to, and including, 1.4.4, update to version 1.4.5 to resolve the issue. As a temporary workaround, consider restricting access to the plugin to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2023-6933

Affected Products

Better Search Replace