Lucene search

K
cvelistWPScanCVELIST:CVE-2023-0255
HistoryFeb 13, 2023 - 2:32 p.m.

CVE-2023-0255 Enable Media Replace < 4.0.2 - Author+ Arbitrary File Upload

2023-02-1314:32:21
WPScan
www.cve.org
6
cve-2023-0255
wordpress plugin
arbitrary file upload
php shells

AI Score

9

Confidence

High

EPSS

0.001

Percentile

43.5%

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Enable Media Replace",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "4.0.2"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

AI Score

9

Confidence

High

EPSS

0.001

Percentile

43.5%