CVE-2023-4643
The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog
- Affected products
- Enable Media Replace
- Shortpixel Enable Media Replace
- < 4.1.3
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.8% (55th percentile)
- NVD status
- Modified
- Published
- 2023-10-16
CVE-2023-4643 at NVD
1 known exploit for CVE-2023-4643
Proof-of-concept code and exploit modules indexed by Sploitus