CVE-2023-0255: Enable Media Replace < 4.0.2 - Author+ Arbitrary File Upload
Published Feb 13, 2023
·Updated
The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
Affected Software
1 affected component
ShortPixel Enable Media Replace Wordpress<4.0.2
Event History
Feb 13, 2023
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-0255?
CVE-2023-0255 is a vulnerability found in the Enable Media Replace WordPress plugin before version 4.0.2.
2
What is the severity of CVE-2023-0255?
CVE-2023-0255 has a severity score of 8.8, classified as high.
3
How does CVE-2023-0255 affect software?
CVE-2023-0255 affects the Shortpixel Enable Media Replace WordPress plugin up to version 4.0.2.
4
What is the description of CVE-2023-0255?
CVE-2023-0255 allows authors to upload arbitrary files to the site, potentially enabling them to upload PHP shells on affected sites.
5
How can I fix CVE-2023-0255?
To fix CVE-2023-0255, update the Enable Media Replace WordPress plugin to version 4.0.2 or later.