26 Jan 2024

Contrary to Bleeping Computer Story, Hackers Don’t Seem to Have Targeted Security Issue in Better Search Replace

Yesterday, the Bleeping Computer ran a story headlined “Hackers target WordPress database plugin active on 1 million sites,” written by Bill Toulas. The plugin being referenced was Better Search Replace, which had a security change in the latest version. There doesn’t appear to have been a hacker targeting it, though.

The only thing backing up that headline was described this way: [Read more]

27 Feb 2019

Vulnerability Details: Cross-Site Request Forgery (CSRF)/Local File Inclusion (LFI) in Better Search Replace

The latest version of Better Search Replace has two changelog entries that are security related, one though appears unrelated to a vulnerability, but the other, “Security: Pass template filenames through sanitize_file_name()”, relates to fixing a cross-site request forgery (CSRF)/local file inclusion (LFI) vulnerability.


[Read more]