Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS.

This issue affects Enable Media Replace: from n/a through 4.2.1.
Published: 2026-07-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Enable Media Replace WordPress plugin contains a stored cross‑site scripting flaw, classified as CWE‑79, caused by improper neutralization of user input during web page generation. An attacker with sufficient privileges to replace media can upload a malicious payload through the plugin’s interface; the payload is persisted and later rendered unfiltered in the browser of any user viewing the content, allowing execution of arbitrary JavaScript. This can lead to session hijacking, credential theft, and site defacement.

Affected Systems

ShortPixel’s Enable Media Replace plugin, versions up to and including 4.2.1, are susceptible. Versions 4.2.2 and later incorporate a fix that removes the vulnerability, so upgrading to those releases eliminates the risk.

Risk and Exploitability

With a CVSS score of 5.9 the flaw is of medium severity. The EPSS score of less than 1 % suggests a very low but non‑zero probability of exploitation, and the issue is not present in the CISA KEV catalog. The likely attack vector involves a stored input via the plugin’s media replacement feature, requiring an authenticated user with permissions to replace media. Given the required user privileges and the minimal exploitation probability, the overall risk to environments that have not patched is moderate.

Generated by OpenCVE AI on August 1, 2026 at 22:53 UTC.

Remediation

Vendor Solution

Update the WordPress Enable Media Replace Plugin to the latest available version (at least 4.2.2).


OpenCVE Recommended Actions

  • Upgrade the Enable Media Replace plugin to version 4.2.2 or later, which contains the vendor‑supplied fix.
  • If an upgrade cannot be performed immediately, temporarily remove or disable the plugin until the patch is installed to prevent attackers from leveraging the flaw.
  • Restrict the media replacement capability to a minimal set of trusted administrators, limiting the opportunity for malicious payload insertion.
  • Consider deploying a content‑security‑policy that blocks inline scripts and enabling X‑XSS‑Protection headers to reduce the impact of any residual stored scripts.

Generated by OpenCVE AI on August 1, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Shortpixel
Shortpixel enable Media Replace
Wordpress
Wordpress wordpress
Vendors & Products Shortpixel
Shortpixel enable Media Replace
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS. This issue affects Enable Media Replace: from n/a through 4.2.1.
Title WordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Shortpixel Enable Media Replace
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:33:30.032Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57722

cve-icon Vulnrichment

Updated: 2026-07-02T14:33:24.862Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T18:16:35.240

Modified: 2026-07-02T15:17:10.340

Link: CVE-2026-57722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T23:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')