Malicious activity targeting a critical severity flaw in the ‘Better Search Replace’ WordPress plugin has been detected, with researchers observing thousands of attempts in the past 24 hours. Better Search Replace is a WordPress plugin with more than one million installations that helps with search and replace operations in databases when moving websites to new domains or servers. Admins can use it to search and replace specific text in the database or handle serialized data, and it provides selective replacement options, support for WordPress Multisite, and also includes a “dry run” option to make sure that everything works fine. The plugin vendor, WP Engine, released version 1.4.5 last week to address a critical-severity PHP object injection vulnerability tracked as CVE-2023-6933. The security issue stems from deserializing untrusted input and allows unauthenticated attackers to inject a PHP object. Successful exploitation could lead to code execution, access to sensitive data, file manipulation or deletion, and triggering an infinite loop denial of service condition. The description of the flaw in Wordfence’s tracker states that Better Search Replace isn’t directly vulnerable but can be exploited to execute code, retrieve sensitive data, or delete files if another plugin or theme on the same site contains the Property Oriented Programming (POP) chain. The exploitability of PHP object injection vulnerabilities often relies on the presence of a suitable POP chain that can b...
Hackers target WordPress database plugin active on 1 million sites
BleepingComputer
·Bill Toulas
·Published Jan 25, 2024
·Updated
Affected Software
1 affected component
WP Engine Better Search Replace=1.4.4
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses malicious attacks targeting a critical vulnerability in the Better Search Replace WordPress plugin.
2
What security implications are discussed in the article?
The article highlights the exploitation of a critical flaw that could lead to unauthorized database access on websites using the plugin.
3
What products or software are affected by this security issue?
The affected product is the Better Search Replace WordPress plugin, specifically version 1.4.4.
4
How many websites are using the vulnerable plugin?
The Better Search Replace plugin is active on approximately 1 million WordPress sites.
5
What actions should website owners take in response to this vulnerability?
Website owners should update the Better Search Replace plugin to the latest version to mitigate potential security risks.