{"error":0,"message":null,"data":{"name":"Enable Media Replace","plugin":"enable-media-replace","link":"https:\/\/wordpress.org\/plugins\/enable-media-replace\/","latest":"1787235840","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"3038074da997b5ec6458d49f8acc4424b976a81dce67648bf9453a1d9ad6fe69","name":"Enable Media Replace [enable-media-replace] < 2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"998cd782c633045e5da1cdac6b7b7cd2ce8eb0d2","name":"WordPress  Enable Media Replace Plugin - Multiple Vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-multiple-vulnerabilities","description":"In general, impact of this plugin is information retrieval and manipulation, arbitrary code execution.\r\nMore details: there exist multiple vulnerabilities in  Enable Media Replace plugin for WordPress: \r\n1. Users can perform SQL injection attacks against the plugin. \r\n2. Users can upload arbitrary files (for the example, PHP files) to retrieve or change important information in the SQL database.","date":"2011-02-09"}],"impact":[]},{"uuid":"7faa4128baad049e1ca61c59c9d47ceb1c954b45ac6772b8f0e6ebcfa6af0a2a","name":"Enable Media Replace [enable-media-replace] < 4.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-2554","name":"CVE-2022-2554","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-2554","description":"[en] The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example","date":"2022-10-10"},{"id":"a201e46322d701efeec4d65aa091f7448ed335ad","name":"Enable Media Replace <= 3.6.3 - Authenticated (Administrator+) Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-363-authenticated-administrator-path-traversal","description":"The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and including, 3.6.3. This makes it possible for authenticated attackers, with administrator-level permissions and above, to move files on the affected site's server outside of the webroot.","date":"2022-09-14"},{"id":"4aeb95021d36989bf4e6aa2a8f0613c7e691c3fe","name":"WordPress  Enable Media Replace Plugin  <= 3.6.3 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-3-6-3-auth-path-traversal-vulnerability","description":"Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.0.0).\nRaad Haddad (Cloudyrion GmbH) discovered and reported this Directory Traversal vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files\/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 4.0.0.","date":"2023-09-14"},{"id":"5872f4bf-f423-4ace-b8b6-d4cc4f6ca8d9","name":"Enable Media Replace &lt; 4.0.0 - Admin+ Path Traversal","link":"https:\/\/wpscan.com\/vulnerability\/5872f4bf-f423-4ace-b8b6-d4cc4f6ca8d9","description":"The plugin does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"4.9","severity":"m","exploitable":"1.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"1.2","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}]}},{"uuid":"f20ed17e8c8362f82c24bb23de84166ea04998fcc49af4ca67a9ddeafcd246f9","name":"Enable Media Replace [enable-media-replace] < 2.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2071476a-d6de-4035-82e5-a85f73f3e3d3","name":"Enable Media Replace &lt;= 2.3 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/2071476a-d6de-4035-82e5-a85f73f3e3d3","description":"The Enable Media Replace WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.","date":null}],"impact":[]},{"uuid":"6f5a99cb8e488dd187b24b7eff8570f293a9518f80262834ca1a37b6948f607e","name":"Enable Media Replace [enable-media-replace] < 4.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-0255","name":"CVE-2023-0255","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-0255","description":"[en] The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.","date":"2023-02-13"},{"id":"d56d3b38a06a76c3a7b65a864f57123ca9636183","name":"Enable Media Replace <= 4.0.1 - Authenticated (Author+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-401-authenticated-author-arbitrary-file-upload","description":"The Enable Media Replace plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with author-level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2023-01-17"},{"id":"ab917bca1bd1e0b1a1142dec6438555e237331d2","name":"WordPress  Enable Media Replace Plugin  < 4.0.2 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-4-0-2-author-arbitrary-file-upload-vulnerability","description":"Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.0.2).\ndc11  discovered and reported this Arbitrary File Upload vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 4.0.2.","date":"2023-01-18"},{"id":"b0239208-1e23-4774-9b8c-9611704a07a0","name":"Enable Media Replace &lt; 4.0.2 - Author+ Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/b0239208-1e23-4774-9b8c-9611704a07a0","description":"The plugin does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ef2fd287f3dfe8ef6e2aab81d469772538de17ba081e393e27435fa377f48c5a","name":"Enable Media Replace [enable-media-replace] < 4.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"df3e2fab6a5af3b9e0d27a3576fbf0a2a4fd63ea","name":"Enable Media Replace <= 4.1.2 - Authenticated(Author+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-412-authenticatededitor-php-object-injection","description":"The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.2 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-09-14"},{"id":"CVE-2023-4643","name":"CVE-2023-4643","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4643","description":"[en] The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog","date":"2023-10-16"},{"id":"d9125604-2236-435c-a67c-07951a1fc5b1","name":"Enable Media Replace &lt; 4.1.3 - Author+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/d9125604-2236-435c-a67c-07951a1fc5b1","description":"The plugin unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"99672aafcf34617d5b184f4d06993683a153418fbb335f90094467e9585b51b9","name":"Enable Media Replace [enable-media-replace] < 4.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f4b1dd6a3e69c6d6edbf516b825332a3724c8798","name":"WordPress  Enable Media Replace Plugin  < 4.1.3 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-4-1-2-authenticated-editor-php-object-injection-vulnerability","description":"Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.1.3).\nUnknown discovered and reported this PHP Object Injection vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 4.1.3.","date":"2023-09-15"}],"impact":[]},{"uuid":"1d2fc56f7e0999ca7a637f79396fa4e02268434538a5b62e0946c83c4788d267","name":"Enable Media Replace [enable-media-replace] < 4.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6737","name":"CVE-2023-6737","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6737","description":"[en] The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploiting this vulnerability requires the attacker to know the ID of an attachment uploaded by the user they are attacking.","date":"2024-01-11"},{"id":"403901f3f57927b3c374e3589413bee060a93961","name":"Enable Media Replace <= 4.1.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-414-reflected-cross-site-scripting","description":"The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploiting this vulnerability requires the attacker to know the ID of an attachment uploaded by the user they are attacking.","date":"2023-12-18"},{"id":"172a3daa19816a66189155658a1d31b440d059bc","name":"WordPress  Enable Media Replace Plugin  <= 4.1.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-4-1-4-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.1.5).\nNex Team discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.1.5.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-14"},{"id":"d7c22e12-5c12-4aa7-8b4a-40eca8075e74","name":"Enable Media Replace &lt; 4.1.5 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/d7c22e12-5c12-4aa7-8b4a-40eca8075e74","description":"The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploiting this vulnerability requires the attacker to know the ID of an attachment uploaded by the user they are attacking.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b3eb5041add6c6d10fe5b37fe22c7fd6052bd791c780d1c4a9ce44f5802bb804","name":"Enable Media Replace [enable-media-replace] < 4.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-31081","name":"CVE-2025-31081","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-31081","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n\/a through 4.1.5.","date":"2025-04-01"},{"id":"f9959f791e6a89d6740485bea607ea40df60e836","name":"WordPress Enable Media Replace Plugin <= 4.1.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/enable-media-replace\/vulnerability\/wordpress-enable-media-replace-plugin-4-1-5-reflected-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Enable Media Replace Plugin <= 4.1.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Enable Media Replace<\/p><p>Fixed in version 4.1.6 <\/p><p>Affected Version <= 4.1.5<\/p><p>CVE: CVE-2025-31081<\/p>","date":"2025-04-01"},{"id":"025751169a22ff833ab44fca74ff0cb7f44ae8fd","name":"Enable Media Replace <= 4.1.5 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-415-reflected-cross-site-scripting","description":"The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-04-01"},{"id":"EUVD-2025-9471","name":"EUVD-2025-9471","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-9471","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n\/a through 4.1.5.","date":"2025-04-01"}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":null,"impact":null}}},{"uuid":"67bdff8957bc744873f8dd568bf26a150155abfec215cdd7c257fdd39691af27","name":"Enable Media Replace [enable-media-replace] < 4.1.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9496","name":"Enable Media Replace <= 4.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9496","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"3320325ba21463c4a2ef626505750bf9e156fec5","name":"Enable Media Replace <= 4.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-416-authenticated-contributor-stored-cross-site-scripting-via-file-modified-shortcode","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-10"},{"id":"EUVD-2025-33820","name":"EUVD-2025-33820","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-33820","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-11"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"787cceeca78d825568355388c2b0960cb89179d2ef26b129834a53fd386bd1a7","name":"Enable Media Replace [enable-media-replace] < 4.1.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2732","name":"Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2732","description":"The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.","date":"0000-00-00"},{"id":"4fd54b5c8520c8a1bc26d8488d804e364b8f9d68","name":"Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-417-improper-authorization-to-authenticated-author-arbitrary-attachment-change-via-background-replace","description":"The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.","date":"2026-03-03"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e6eba7f5d66d3c7f034436aa8405abff510b4e92724afad0ef0c0910011c1b52","name":"Enable Media Replace [enable-media-replace] < 4.1.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-5714","name":"CVE-2026-5714","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-5714","description":"[en] The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018location_dir\u2019 parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-09"},{"id":"5411e176533f601c3b4bcc9c4984698d63c68be7","name":"Enable Media Replace <= 4.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-418-authenticated-author-stored-cross-site-scripting-via-location-dir-parameter","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018location_dir\u2019 parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-06-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"723a62143073a255c5966693037f2be242cc119cbb8f7c3f95ec5c9295789077","name":"Enable Media Replace [enable-media-replace] < 4.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-57722","name":"CVE-2026-57722","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-57722","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS.\n\nThis issue affects Enable Media Replace: from n\/a through 4.2.1.","date":"2026-07-01"},{"id":"b30d0cf95a977c5727d0a1afdc3e7dec912e0138","name":"Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/c8fe4c70-c196-4f20-b787-bea223726fab","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-07-01"},{"id":"e5aa7ac8c9854b214ede604b468ef72cab299aa0","name":"Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/enable-media-replace\/enable-media-replace-421-authenticated-editor-stored-cross-site-scripting","description":"The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2026-06-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1782973723"}