Security Advisory

CVE-2023-4643

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-10-16 19:38:58
Last updated 2025-04-23 16:13:57
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog