Stored Cross-Site Scripting in Enable Media Replace Plugin for WordPress
CVE-2025-9496
6.4MEDIUM
What is CVE-2025-9496?
The Enable Media Replace plugin for WordPress is susceptible to a stored cross-site scripting vulnerability caused by inadequate input sanitization and output escaping within the plugin's file_modified shortcode. This flaw affects versions up to and including 4.1.6, enabling authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts execute when users access the compromised pages, potentially compromising user data and site integrity.
Affected Version(s)
Enable Media Replace * <= 4.1.6