Impact
The Enable Media Replace plugin for WordPress allows authenticated users with Author level or higher to inject arbitrary JavaScript via the ‘location_dir’ field. The injected script is stored and executed on any page that references the compromised media, allowing attackers to hijack user sessions, deface content, or redirect traffic. This is a classic Stored XSS flaw identified as CWE‑79, which directly impacts the confidentiality, integrity, and availability of the WordPress site for all visitors.
Affected Systems
The vulnerability applies to all installed versions of Enable Media Replace up to and including 4.1.8, released by the Shortpixel Vendor. Users running any of these versions on WordPress deployments are affected; a specific version list is not available beyond the maximum vulnerable version.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation. Nonetheless, because any authenticated Author or higher user can inject scripts, the risk to sites with multiple content editors is significant. The attacker must have legitimate WordPress credentials; no privilege escalation beyond the author's role is required.
OpenCVE Enrichment