CVE-2023-0255
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
- Affected products
- Enable Media Replace
- Shortpixel Enable Media Replace
- < 4.0.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.1% (63th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2023-02-13
CVE-2023-0255 at NVD
1 known exploit for CVE-2023-0255
Proof-of-concept code and exploit modules indexed by Sploitus