Better Search Replace <= 1.4.4 - Unauthenticated PHP Object Injection
90Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.8epss 68%
from disclosure to weapon0 days
Published on NVDFeb 5
1st PoCJan 28
VulnCheckJan 25
exploitation probability
68%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
wpengine · Better Search Replacepublic PoCs found — 2
vulncheckvulncheck.com/xdb/a42df92e4069unverifiedvulncheckvulncheck.com/xdb/f19fb1bb15e7unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://plugins.trac.wordpress.org/browser/better-search-replace/trunk/includes/class-bsr-db.php#L334https://plugins.trac.wordpress.org/changeset/3023674/better-search-replace/trunk/includes/class-bsr-db.phphttps://www.wordfence.com/threat-intel/vulnerabilities/id/895f2db1-a2ed-4a17-a4f6-cd13ee8f84af?source=cve