CVE-2023-4643

The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:shortpixel:enable_media_replace:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-10-16 20:15

Updated : 2023-11-07 04:22


NVD link : CVE-2023-4643

Mitre link : CVE-2023-4643

CVE.ORG link : CVE-2023-4643


JSON object : View

Products Affected

shortpixel

  • enable_media_replace
CWE

No CWE.