CVE-2023-0255

Severity
8.8HIGH
EPSS
1.4%
top 19.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13

Description

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Enable Media Replace < 4.0.2 - Author+ Arbitrary File Upload2023-02-13
GHSA
GHSA-j47r-gcvh-59g7: The Enable Media Replace WordPress plugin before 42023-02-13
CVE-2023-0255 (HIGH CVSS 8.8) | The Enable Media Replace WordPress | cvebase.io