Enable Media Replace <= 4.2.1 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 4.4
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Jul 1, 2026
CVE-2026-57722 on NVD →
Enable Media Replace <= 4.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter
medium
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to i...
- CVSS:
- 6.4
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.9
- Disclosed:
- Jun 8, 2026
CVE-2026-5714 on NVD →
Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace
medium
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above,...
- CVSS:
- 5.4
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Mar 3, 2026
CVE-2026-2732 on NVD →
Enable Media Replace <= 4.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode
medium
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modified shortcode in all versions up to, and including, 4.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- Oct 10, 2025
CVE-2025-9496 on NVD →
Enable Media Replace <= 4.1.5 - Reflected Cross-Site Scripting
medium
The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Apr 1, 2025
CVE-2025-31081 on NVD →
Enable Media Replace [enable-media-replace] < 4.1.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Reflected XSS. This issue affects Enable Media Replace: from n/a through 4.1.5.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Apr 1, 2025
CVE-2025-31081 on NVD →
Enable Media Replace [enable-media-replace] < 4.1.5
unknown
[en] The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Jan 11, 2024
CVE-2023-6737 on NVD →
Enable Media Replace <= 4.1.4 - Reflected Cross-Site Scripting
medium
The Enable Media Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the SHORTPIXEL_DEBUG parameter in all versions up to, and including, 4.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 4.7
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.5
- Disclosed:
- Dec 18, 2023
CVE-2023-6737 on NVD →
Enable Media Replace [enable-media-replace] < 4.1.3
unknown
[en] The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Oct 16, 2023
CVE-2023-4643 on NVD →
Enable Media Replace [enable-media-replace] < 4.1.3
unknown
Update the WordPress Enable Media Replace plugin to the latest available version (at least 4.1.3).
Unknown discovered and reported this PHP Object Injection vulnerability in WordPress Enable Media Replace Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of serv...
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Sep 15, 2023
Enable Media Replace <= 4.1.2 - Authenticated(Author+) PHP Object Injection
medium
The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.2 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerable plug...
- CVSS:
- 6.6
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Sep 14, 2023
CVE-2023-4643 on NVD →
Enable Media Replace [enable-media-replace] < 4.1.3
unknown
The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.2 via deserialization of untrusted input in post content. This allows authenticated attackers with editor capabilities or above to inject a PHP Object. No POP chain is present in the vulnerable plug...
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
- Disclosed:
- Sep 14, 2023
Enable Media Replace [enable-media-replace] < 4.0.2
unknown
[en] The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Feb 13, 2023
CVE-2023-0255 on NVD →
Enable Media Replace <= 4.0.1 - Authenticated (Author+) Arbitrary File Upload
high
The Enable Media Replace plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 4.0.1. This makes it possible for authenticated attackers, with author-level permissions and above, to upload arbitrary files on the affected sites server which may make remote code execution possible...
- CVSS:
- 8.8
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Jan 17, 2023
CVE-2023-0255 on NVD →
Enable Media Replace [enable-media-replace] < 4.0.0
unknown
[en] The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
- Affected:
- up to 4.0.0
- Fixed in:
- 4.0.0
- Disclosed:
- Oct 10, 2022
CVE-2022-2554 on NVD →
Enable Media Replace <= 3.6.3 - Authenticated (Administrator+) Path Traversal
medium
The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and including, 3.6.3. This makes it possible for authenticated attackers, with administrator-level permissions and above, to move files on the affected site's server outside of the webroot.
- CVSS:
- 6.8
- Affected:
- up to 3.6.3
- Fixed in:
- 4.0.0
- Disclosed:
- Sep 14, 2022
CVE-2022-2554 on NVD →
Enable Media Replace [enable-media-replace] < 2.4
unknown
In general, impact of this plugin is information retrieval and manipulation, arbitrary code execution.
More details: there exist multiple vulnerabilities in Enable Media Replace plugin for WordPress:
1. Users can perform SQL injection attacks against the plugin.
2. Users can upload arbitrary files (for the exampl...
- Affected:
- up to 2.4
- Fixed in:
- 2.4
- Disclosed:
- Feb 9, 2011
Enable Media Replace [enable-media-replace] < 2.4
unknown
The Enable Media Replace WordPress plugin was affected by a Multiple Vulnerabilities security vulnerability.
- Affected:
- up to 2.4
- Fixed in:
- 2.4
Enable Media Replace [enable-media-replace] < 4.1.7
unknown
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
CVE-2025-9496 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database