CVE-2022-2554: Enable Media Replace < 4.0.0 - Admin+ Path Traversal
Published Oct 10, 2022
·Updated
The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example
Affected Software
1 affected component
ShortPixel Enable Media Replace Wordpress<4.0.0
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-2554?
CVE-2022-2554 is a vulnerability in the Enable Media Replace WordPress plugin that allows high privilege users to move renamed files outside of the web root directory.
2
How severe is CVE-2022-2554?
CVE-2022-2554 has a severity rating of 4.9, which is considered medium.
3
What is the affected software for CVE-2022-2554?
The affected software for CVE-2022-2554 is the Enable Media Replace WordPress plugin version up to 4.0.0.
4
What is the CWE of CVE-2022-2554?
The CWE of CVE-2022-2554 is CWE-22.
5
How can I fix CVE-2022-2554?
To fix CVE-2022-2554, update the Enable Media Replace WordPress plugin to version 4.0.0 or higher.