The Better Search plugin for WordPress is vulnerable to a security risk known as SQL Injection. This is a problem for users of the plugin who have versions up to and including 2.2.3. The vulnerability occurs because the plugin does not properly protect the user-supplied parameters and does not check the existing SQL query. This means that attackers who are not authorized to do so are able to add extra SQL queries to the existing ones, which can be used to access sensitive information from the database.