Vulnerability record · CVE-2023-6933 · published 5 February 2024
CVE-2023-6933: Better Search Replace WordPress plugin PHP object injection
Wpengine · Better Search Replace
The Better Search Replace plugin for WordPress deserializes untrusted input in all versions up to and including 1.4.4, allowing PHP object injection. The plugin itself contains no POP chain, so real impact depends on a gadget chain being present in another installed plugin or theme.
Description
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with no privileges required and high EPSS, but exploitation depends on an external POP chain and requires user interaction.
What it is
The Better Search Replace plugin for WordPress deserializes untrusted input in all versions up to and including 1.4.4, allowing PHP object injection. The plugin itself contains no POP chain, so real impact depends on a gadget chain being present in another installed plugin or theme.
Impact
An attacker can inject a PHP object; if a POP chain exists elsewhere on the site, this could lead to arbitrary file deletion, sensitive data retrieval, or code execution. Without a usable chain, the injection alone yields no direct impact.
Attack surface
Reachable over the network via the vulnerable deserialization path; the CVSS vector indicates no privileges required but user interaction is required. The description does not specify the exact request or parameter, so the precise entry point is not documented here.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.68047, 99.3rd percentile) and references include an Exploit tag, indicating public exploit interest, though the plugin lacks its own POP chain.
What to do
- Update Better Search Replace to a version newer than 1.4.4 (patch referenced in changeset 3023674).
- If immediate patching is not possible, deactivate or remove the plugin until it can be updated.
- Audit installed plugins and themes for known PHP object injection gadget chains that could complete the exploit.
- Restrict access to WordPress administrative functionality and monitor for unexpected file changes or data access.
Detection
- Monitor web requests for serialized PHP object payloads (e.g., O: patterns) targeting the plugin's endpoints.
- Watch for unexpected file deletions or reads of sensitive files on the WordPress host.
- Review logs for anomalous POST requests to Better Search Replace related paths.
- Alert on plugin file changes or new plugin installations that could introduce POP chains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-6933 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.