• News/
  • https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-database-plugin-active-on-1-million-sites/

Hackers target WordPress database plugin active on 1 million sites

BleepingComputer
·
Bill Toulas
·
Published Jan 25, 2024
·
Updated

Malicious activity targeting a critical severity flaw in the ‘Better Search Replace’ WordPress plugin has been detected, with researchers observing thousands of attempts in the past 24 hours. Better Search Replace is a WordPress plugin with more than one million installations that helps with search and replace operations in databases when moving websites to new domains or servers. Admins can use it to search and replace specific text in the database or handle serialized data, and it provides selective replacement options, support for WordPress Multisite, and also includes a “dry run” option to make sure that everything works fine. The plugin vendor, WP Engine, released version 1.4.5 last week to address a critical-severity PHP object injection vulnerability tracked as CVE-2023-6933. The security issue stems from deserializing untrusted input and allows unauthenticated attackers to inject a PHP object. Successful exploitation could lead to code execution, access to sensitive data, file manipulation or deletion, and triggering an infinite loop denial of service condition. The description of the flaw in Wordfence’s tracker states that Better Search Replace isn’t directly vulnerable but can be exploited to execute code, retrieve sensitive data, or delete files if another plugin or theme on the same site contains the Property Oriented Programming (POP) chain. The exploitability of PHP object injection vulnerabilities often relies on the presence of a suitable POP chain that can b...

Read full article

Affected Software

1 affected component
WP Engine Better Search Replace=1.4.4
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses malicious attacks targeting a critical vulnerability in the Better Search Replace WordPress plugin.

2

What security implications are discussed in the article?

The article highlights the exploitation of a critical flaw that could lead to unauthorized database access on websites using the plugin.

3

What products or software are affected by this security issue?

The affected product is the Better Search Replace WordPress plugin, specifically version 1.4.4.

4

How many websites are using the vulnerable plugin?

The Better Search Replace plugin is active on approximately 1 million WordPress sites.

5

What actions should website owners take in response to this vulnerability?

Website owners should update the Better Search Replace plugin to the latest version to mitigate potential security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203