Junglewise Threat Intelligence

CVE-2026-57722: ShortPixel Enable Media Replace Stored XSS

CVE-2026-57722 · Severity: medium · CVSS 5.9 · Published 2026-07-01

Vendors: ShortPixel.

Executive brief

ShortPixel Enable Media Replace is a WordPress plugin used to easily swap old media files with new ones in the site's library. A security vulnerability in versions up to 4.2.1 allows an attacker with high-level administrative access to inject malicious scripts into the website. If a site visitor or another administrator views the affected page, these scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the ShortPixel Enable Media Replace plugin for WordPress (versions up to 4.2.1). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject arbitrary web scripts. Exploitation requires high-level privileges (such as an Editor or Administrator role) and some degree of user interaction from another user. Successful exploitation allows the execution of malicious JavaScript in the context of the victim's browser, which can be used to bypass same-origin policy protections or hijack user sessions. The issue is addressed in version 4.2.2.

Affected products

  • ShortPixel Enable Media Replace up to 4.2.1

Timeline

  • 2026-06-24: other: Reported by researcher Ananda Dhakal
  • 2026-07-01: advisory: Published by Patchstack
  • 2026-07-01: patched: Version 4.2.2 released to address the vulnerability

References

Related threats