Back

CRITICAL

Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection

Published Feb 5, 2024

Description

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 5, 2024
Updated Apr 8, 2026
Reserved Dec 18, 2023
CISA Vulnrichment
Updated Aug 22, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a