HomeSecurityBetter Search Replace: Hackers target vulnerability in WordPress plugin

Better Search Replace: Hackers target vulnerability in WordPress plugin

Security researchers have observed, in recent hours, thousands of attempts to exploit a critical vulnerability in the WordPress plugin "Better Search Replace".

Better Search Replace vulnerability

Better Search Replace is a WordPress plugin with over a million installations. It is used for search and replace operations in databases ,when moving websites to new domains or servers. Administrators use it to search and replace specific text in the database or to manipulate serial data.

The plugin vendor, WP Engine, released version 1.4.5 last week to address a critical vulnerability tracked as CVE-2023-6933.

See also: Balada Injector Malware has infected 6,700 WordPress sites

The vulnerability could allow unauthorized attackers to inject a PHP object. The result could be code execution, access sensitive data, modify or delete files, and trigger a denial of service condition.

According to Wordfence, Better Search Replace is not directly vulnerable, but the above can be done if another plugin or theme on the same site contains the Property Oriented Programming (POP) chain.

The ability to exploit vulnerabilities, such as CVE-2023-6933, often relies on the presence of a suitable POP chain that can be triggered by the injected object to perform malicious activities.

Wordfence says it has blocked thousands of attempts to exploit the vulnerability in the last few hours.

The vulnerability affects all versions of the WordPress plugin Better Search Replace up to 1.4.4. It is recommended to upgrade to version 1.4.5 immediately to protect users' systems

See also: POST SMTP Mailer: Vulnerabilities in WordPress plugin – Update immediately!

WordPress plugins

Importance of WordPress protection

Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.

Additionally, an unsecured WordPress site can undermine the trust and credibility you have built with customers . If their data is compromised, they are likely to take legal action against you and switch to other companies.

See also: AI Engine: Vulnerability in WordPress plugin puts 50,000 sites at risk

Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your website and corrupts the content, it can give the impression that you are not doing enough with your website.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining customers , preserving your company’s reputation, and staying on top of the competition.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS