CVE-2023-4643: Enable Media Replace < 4.1.3 - Author+ PHP Object Injection
The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4643?
CVE-2023-4643 is a vulnerability found in the Enable Media Replace WordPress plugin before version 4.1.3. It allows Author+ users to perform PHP Object Injection via the Remove Background feature.
How does CVE-2023-4643 impact users?
CVE-2023-4643 allows Author+ users to exploit the vulnerability and perform PHP Object Injection when a suitable gadget is present on the blog.
What is the severity of CVE-2023-4643?
CVE-2023-4643 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2023-4643?
The Enable Media Replace WordPress plugin versions up to 4.1.3 are affected by CVE-2023-4643.
How can I mitigate CVE-2023-4643?
To mitigate CVE-2023-4643, it is recommended to update the Enable Media Replace WordPress plugin to version 4.1.3 or later.