plugin

Enable Media Replace Vulnerabilities

19 known security issues reported for the Enable Media Replace WordPress plugin. Most recent disclosed Jul 1, 2026.

1 high 8 medium

Running Enable Media Replace on your site? Check whether your installed version is affected.

Scan your site free

Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
4.4
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Jul 1, 2026

CVE-2026-57722 on NVD →

Enable Media Replace <= 4.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter

medium

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to i...

CVSS:
6.4
Affected:
up to 4.1.8
Fixed in:
4.1.9
Disclosed:
Jun 8, 2026

CVE-2026-5714 on NVD →

Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace

medium

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above,...

CVSS:
5.4
Affected:
up to 4.1.7
Fixed in:
4.1.8
Disclosed:
Mar 3, 2026

CVE-2026-2732 on NVD →

Enable Media Replace <= 4.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode

medium

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 4.1.6
Fixed in:
4.1.7
Disclosed:
Oct 10, 2025

CVE-2025-9496 on NVD →

Enable Media Replace <= 4.1.5 - Reflected Cross-Site Scripting

medium

The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...

CVSS:
6.1
Affected:
up to 4.1.5
Fixed in:
4.1.6
Disclosed:
Apr 1, 2025

CVE-2025-31081 on NVD →

Enable Media Replace [enable-media-replace] < 4.1.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.

Affected:
up to 4.1.6
Fixed in:
4.1.6
Disclosed:
Apr 1, 2025

CVE-2025-31081 on NVD →

Enable Media Replace [enable-media-replace] < 4.1.5

unknown

[en] The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Jan 11, 2024

CVE-2023-6737 on NVD →

Enable Media Replace <= 4.1.4 - Reflected Cross-Site Scripting

medium

The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
4.7
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
Dec 18, 2023

CVE-2023-6737 on NVD →

Enable Media Replace [enable-media-replace] < 4.1.3

unknown

[en] The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Oct 16, 2023

CVE-2023-4643 on NVD →

Enable Media Replace [enable-media-replace] < 4.1.3

unknown

Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.1.3). Unknown discovered and reported this PHP Object Injection vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of serv...

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Sep 15, 2023

Enable Media Replace <= 4.1.2 - Authenticated(Author+) PHP Object Injection

medium

The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.2 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerable plug...

CVSS:
6.6
Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Sep 14, 2023

CVE-2023-4643 on NVD →

Enable Media Replace [enable-media-replace] < 4.1.3

unknown

The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.2 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerable plug...

Affected:
up to 4.1.3
Fixed in:
4.1.3
Disclosed:
Sep 14, 2023

Enable Media Replace [enable-media-replace] < 4.0.2

unknown

[en] The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Feb 13, 2023

CVE-2023-0255 on NVD →

Enable Media Replace <= 4.0.1 - Authenticated (Author+) Arbitrary File Upload

high

The Enable Media Replace plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with author-level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible...

CVSS:
8.8
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Jan 17, 2023

CVE-2023-0255 on NVD →

Enable Media Replace [enable-media-replace] < 4.0.0

unknown

[en] The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

Affected:
up to 4.0.0
Fixed in:
4.0.0
Disclosed:
Oct 10, 2022

CVE-2022-2554 on NVD →

Enable Media Replace <= 3.6.3 - Authenticated (Administrator+) Path Traversal

medium

The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and including, 3.6.3. This makes it possible for authenticated attackers, with administrator-level permissions and above, to move files on the affected site's server outside of the webroot.

CVSS:
6.8
Affected:
up to 3.6.3
Fixed in:
4.0.0
Disclosed:
Sep 14, 2022

CVE-2022-2554 on NVD →

Enable Media Replace [enable-media-replace] < 2.4

unknown

In general, impact of this plugin is information retrieval and manipulation, arbitrary code execution. More details: there exist multiple vulnerabilities in Enable Media Replace plugin for WordPress: 1. Users can perform SQL injection attacks against the plugin. 2. Users can upload arbitrary files (for the exampl...

Affected:
up to 2.4
Fixed in:
2.4
Disclosed:
Feb 9, 2011

Enable Media Replace [enable-media-replace] < 2.4

unknown

The Enable Media Replace WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.

Affected:
up to 2.4
Fixed in:
2.4

Enable Media Replace [enable-media-replace] < 4.1.7

unknown
Affected:
up to 4.1.7
Fixed in:
4.1.7

CVE-2025-9496 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database