Vulnerabilities > Wpengine > Better Search Replace > 1.2.8

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2023-6933 Deserialization of Untrusted Data vulnerability in Wpengine Better Search Replace
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input.
network
low complexity
wpengine CWE-502
critical
9.8