The Better Search plugin for WordPress is vulnerable to a security risk called Cross-Site Request Forgery. This means that versions up to, and including, 3.1.0 could be affected. The risk is caused by the plugin not correctly validating something called a “nonce”. This makes it easier for attackers to send a “forged request” to the plugin and clear the cache, if they can trick a site administrator into clicking a link.