Vulnerabilities > CVE-2023-4643 - Unspecified vulnerability in Shortpixel Enable Media Replace

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
shortpixel

Summary

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

Vulnerable Configurations

Part Description Count
Application
Shortpixel
75