Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-0255

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
Attacker Value
Unknown

CVE-2022-2554

Disclosure Date: October 10, 2022 (last updated February 24, 2025)
The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
Attacker Value
Unknown

CVE-2022-29417

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.