๐Ÿ” CVE Alert

CVE-2022-2554

UNKNOWN 0.0

Enable Media Replace < 4.0.0 - Admin+ Path Traversal

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder, which could allow high privilege users such as admin to move them outside to the web root directory via a path traversal attack for example

CWE CWE-22
Vendor unknown
Product enable media replace
Published Oct 10, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for unknown enable media replace

Be the first to know when new unknown vulnerabilities affecting unknown enable media replace are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Enable Media Replace
4.0.0 < 4.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5872f4bf-f423-4ace-b8b6-d4cc4f6ca8d9

Credits

Raad Haddad of Cloudyrion GmbH