Shortpixel Enable Media Replace vulnerabilities

7 known vulnerabilities affecting shortpixel/enable_media_replace.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4UNKNOWN1

Vulnerabilities

Page 1 of 1
CVE-2026-2732MEDIUMCVSS 5.4≤ 4.1.72026-03-04
CVE-2026-2732 [MEDIUM] CWE-862 CVE-2026-2732: The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a
cvelistv5nvd
CVE-2025-9496MEDIUMCVSS 6.4≤ 4.1.62025-10-11
CVE-2025-9496 [MEDIUM] CWE-79 CVE-2025-9496: The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and abov
cvelistv5nvd
CVE-2025-31081UNKNOWN≤ 4.1.52025-04-01
CVE-2025-31081 CWE-79 CVE-2025-31081: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace enable-media-replace allows Reflected XSS.This issue affects Enable Media Replace: from n/a through <= 4.1.5.
cvelistv5nvd
CVE-2023-6737MEDIUMCVSS 6.1≤ 4.1.42024-01-11
CVE-2023-6737 [MEDIUM] CWE-79 CVE-2023-6737: The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can su
cvelistv5nvd
CVE-2023-4643HIGHCVSS 8.8fixed in 4.1.32023-10-16
CVE-2023-4643 [HIGH] CWE-502 CVE-2023-4643: The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Backgr The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog
nvd
CVE-2023-0255HIGHCVSS 8.8fixed in 4.0.22023-02-13
CVE-2023-0255 [HIGH] CWE-434 CVE-2023-0255: The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbit The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
nvd
CVE-2022-2554MEDIUMCVSS 4.9fixed in 4.0.02022-10-10
CVE-2022-2554 [MEDIUM] CWE-22 CVE-2022-2554: The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
nvd