Enable Media Replace <= 4.1.7 - Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace

2026-03-03 18:17
Or Benit

Strategic Overview

Status
Patched in 4.1.8
Affected PluginEnable Media Replace
Affected Version<= 4.1.7
CVSS5.4Medium
CVECVE-2026-2732
View all Enable Media Replace vulnerabilities

Vulnerability Overview

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.

Technical Analysis

REMEDIATION: Update to version 4.1.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C