Description
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.
Problem types
Product status
* (semver)
Timeline
| 2026-02-19: | Vendor Notified |
| 2026-03-03: | Disclosed |
Credits
Or Benit
References
www.wordfence.com/...-67f7-4dbf-8631-f434522f1b53?source=cve
plugins.trac.wordpress.org/...veBackgroundViewController.php
plugins.trac.wordpress.org/...veBackgroundViewController.php
github.com/...ommit/8ca282e68e5fcf8a8e4cecc1f0ab192c42b1dc66
plugins.trac.wordpress.org/...t/3473504/enable-media-replace