WordPress Product Security Update Advisory (CVE-2023-6933)
Overview
An update has been made available to fix vulnerabilities in the Better Search Replace plugin in WordPress. Users of affected versions are advised to update to the latest version.
Affected Products
Versions of the Better Search Replace pluginin WordPress 1.4.4 and earlier
Resolved Vulnerabilities
Unauthenticated PHP object injection vulnerability in the Better Search Replace plugin inWordPress (CVE-2023-6933)
Vulnerability Patches
A vulnerability patch was made available in the January 24, 2024 update. Users of affected versions are advised to update to the latest version.
Better Search Replace Plugin forWordPress version 1.4.5
Referenced Sites
[1] Better Search Replace <= 1.4.4 – Unauthenticated PHP Object Injection
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/better-search-replace/better-search-replace-144-unauthenticated-php-object-injection
[2] Better Search Replace
https://wordpress.org/plugins/better-search-replace/