Executive brief
Enable Media Replace is a WordPress plugin that allows site administrators to easily replace existing media files in their library. A security flaw allows users with Author-level permissions or higher to inject malicious scripts into the site's management interface. If an administrator or another user views the affected page, these scripts could execute, potentially leading to unauthorized actions or data theft.
Technical details
The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'location_dir' parameter. This vulnerability exists in all versions up to and including 4.1.8. An authenticated attacker with Author-level permissions or higher can inject arbitrary web scripts into the database. These scripts will execute in the context of any user's browser who accesses the page where the injected content is displayed. The attack is delivered over the network and does not require interaction from the victim beyond visiting the compromised page.
Affected products
- ShortPixel Enable Media Replace Up to and including 4.1.8
Timeline
- 2026-06-09: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/enable-media-replace/tags/4.1.8/classes/ViewController/UploadViewController.php
- https://plugins.trac.wordpress.org/browser/enable-media-replace/tags/4.1.8/views/screen.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c6e8a78b-01ad-47b2-84e6-4f6ff78c02b6?source=cve