Hackers target WordPress database plugin active on 1 million sites
ID: c428dc1a-5486-5a93-a76c-6ea3d9c91025
STIX ID: report--c428dc1a-5486-5a93-a76c-6ea3d9c91025
Feed Name: Bleeping Computer
Researchers observed thousands of attacks exploiting a critical PHP object injection vulnerability (CVE-2023-6933) in the Better Search Replace WordPress plugin (affecting versions up to 1.4.4). WP Engine released version 1.4.5 to patch the issue, and Wordfence reported blocking over 2,500 exploitation attempts in 24 hours; successful exploitation can enable code execution, sensitive data access, file manipulation/deletion, or DoS if a Property Oriented Programming (POP) chain is available, so administrators should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
