← Vulnerability feed

Vulnerability record · CVE-2023-6933 · published 5 February 2024

CVE-2023-6933: Better Search Replace WordPress plugin PHP object injection

Wpengine · Better Search Replace

The Better Search Replace plugin for WordPress deserializes untrusted input in all versions up to and including 1.4.4, allowing PHP object injection. The plugin itself contains no POP chain, so real impact depends on a gadget chain being present in another installed plugin or theme.

8.8 CVSS 3.1 High EPSS 68% · top 0.7% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with no privileges required and high EPSS, but exploitation depends on an external POP chain and requires user interaction.

What it is

The Better Search Replace plugin for WordPress deserializes untrusted input in all versions up to and including 1.4.4, allowing PHP object injection. The plugin itself contains no POP chain, so real impact depends on a gadget chain being present in another installed plugin or theme.

Impact

An attacker can inject a PHP object; if a POP chain exists elsewhere on the site, this could lead to arbitrary file deletion, sensitive data retrieval, or code execution. Without a usable chain, the injection alone yields no direct impact.

Attack surface

Reachable over the network via the vulnerable deserialization path; the CVSS vector indicates no privileges required but user interaction is required. The description does not specify the exact request or parameter, so the precise entry point is not documented here.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is high (0.68047, 99.3rd percentile) and references include an Exploit tag, indicating public exploit interest, though the plugin lacks its own POP chain.

What to do

  • Update Better Search Replace to a version newer than 1.4.4 (patch referenced in changeset 3023674).
  • If immediate patching is not possible, deactivate or remove the plugin until it can be updated.
  • Audit installed plugins and themes for known PHP object injection gadget chains that could complete the exploit.
  • Restrict access to WordPress administrative functionality and monitor for unexpected file changes or data access.

Detection

  • Monitor web requests for serialized PHP object payloads (e.g., O: patterns) targeting the plugin's endpoints.
  • Watch for unexpected file deletions or reads of sensitive files on the WordPress host.
  • Review logs for anomalous POST requests to Better Search Replace related paths.
  • Alert on plugin file changes or new plugin installations that could introduce POP chains.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-6933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed9.3CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 PHP object injection RCEMirasvit Full Page Cache Warmer for Magento 2 before 1.11.12 passes the CacheWarmer cookie to PHP's native unserialize() without restriction, allowin…KEVEPSS 2.1%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed

Source: NIST National Vulnerability Database (record CVE-2023-6933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.