Impact
The Enable Media Replace WordPress plugin contains a stored cross‑site scripting flaw, classified as CWE‑79, caused by improper neutralization of user input during web page generation. An attacker with sufficient privileges to replace media can upload a malicious payload through the plugin’s interface; the payload is persisted and later rendered unfiltered in the browser of any user viewing the content, allowing execution of arbitrary JavaScript. This can lead to session hijacking, credential theft, and site defacement.
Affected Systems
ShortPixel’s Enable Media Replace plugin, versions up to and including 4.2.1, are susceptible. Versions 4.2.2 and later incorporate a fix that removes the vulnerability, so upgrading to those releases eliminates the risk.
Risk and Exploitability
With a CVSS score of 5.9 the flaw is of medium severity. The EPSS score of less than 1 % suggests a very low but non‑zero probability of exploitation, and the issue is not present in the CISA KEV catalog. The likely attack vector involves a stored input via the plugin’s media replacement feature, requiring an authenticated user with permissions to replace media. Given the required user privileges and the minimal exploitation probability, the overall risk to environments that have not patched is moderate.
OpenCVE Enrichment