Showing 1 vulnerability on this page for Better Search Replace

Signals CISA KEV Ransomware Nuclei
wpengine vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

CWE-502Feb 5, 20241 related artifact
CVSS8.8v3.1EPSS68%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX