8.8
CVSSv3

CVE-2023-0255

Published: 13/02/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Enable Media Replace WordPress plugin prior to 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

Vulnerable Product Search on Vulmon Subscribe to Product

shortpixel enable media replace

Github Repositories

Mass Exploit - CVE-2023-0255 < WordPress < Enable Media+Plugin < Unauthenticated Arbitrary File Upload / Webshell Upload

CVE-2023-0255-PoC Mass Exploit - CVE-2023-0255 &lt; WordPress &lt; Enable Media+Plugin &lt; Unauthenticated Arbitrary File Upload Community : tme/codeb0ss Dork : inurl: wp-content/plugins/enable-media/ Infected Sites : 600K Wordpress Sites [This is published for educational and informational purposes only and the developers accept no responsibility for the