Aller au contenu

Fiche vulnérabilité

CVE-2023-0255 : faille élevée shortpixel enable media replace (CVSS 8.8)

Description

The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
13 févr. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • shortpixel enable media replace

Références

Rechercher une autre vulnérabilité dans la base CVE