CVE-2025-31081Cross-site Scripting in Enable Media Replace

Severity
7.3HIGH
No vector
EPSS
0.3%
top 50.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace enable-media-replace allows Reflected XSS.This issue affects Enable Media Replace: from n/a through <= 4.1.5.

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
WordPress Enable Media Replace plugin <= 4.1.5 - Reflected Cross Site Scripting (XSS) vulnerability2025-04-01
GHSA
GHSA-hjj5-539p-596j: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected2025-04-01

📋Vendor Advisories

1
Microsoft
Xorg-x11-server: heap buffer overread/data leakage in procxipassivegrabdevice2024-04-09
CVE-2025-31081 — Cross-site Scripting | cvebase