Description
WordPress Plugin Better Search is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Better Search version 2.5.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.5.3 or latest
References
https://blog.nintechnet.com/multiple-wordpress-plugins-fixed-csrf-vulnerabilities-part-1/
https://plugins.svn.wordpress.org/better-search/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Event Registration 'event_id' Parameter SQL Injection (5.44)
WordPress Plugin MW WP Form Cross-Site Scripting (2.10.0)
WordPress Plugin Register Plus 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities (3.5.1)
WordPress Plugin 10Web Map Builder for Google Maps SQL Injection (1.0.72)