Easy Replace Image <= 3.5.2 - Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement
medium
The Easy Replace Image plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.5.2. This is due to missing capability checks on the `image_replacement_from_url` function that is hooked to the `eri_from_url` AJAX action. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 3.5.2
- Fixed in:
- 3.5.3
- Disclosed:
- Jan 27, 2026
CVE-2026-1298 on NVD →
Easy Replace Image <= 3.5.0 - Authenticated (Contributor+) Server-Side Request Forgery
medium
The Easy Replace Image plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application which can be...
- CVSS:
- 6.4
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- May 7, 2025
CVE-2025-47483 on NVD →
Easy Replace Image [easy-replace-image] < 3.5.1
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Iulia Cazan Easy Replace Image allows Server Side Request Forgery. This issue affects Easy Replace Image: from n/a through 3.5.0.
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- May 7, 2025
CVE-2025-47483 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database