LH Copy Media File

LH Copy Media File has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for LH Copy Media File has a vendor fix available, so running the current release closes it.

All of these findings were reported by Colin Xu. LH Copy Media File is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all LH Copy Media File vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2024-9220

LH Copy Media File <= 1.08 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
LH Copy Media File banner
Latestv1.11

LH Copy Media File

shawfactor

Author

shawfactor

4.0(7)
80/100
Last Updated
2024-10-01 (2y ago)
Active Installs
800+
Downloads
16,285
Requires WP
4.1+
Requires PHP
0+
Tested up to
WP 6.6.7
Created
2016-03-31 (11y ago)

This plugin allows you to create duplicate images in the media library, rather than having to create a new copy of the image and upload it to WordPress again. It works by copying the post and its metadata into a totally new file in the media manager. Any changes you make to the new copy of the attachment — updating the caption or cropping, for example, will only be applied to the new attachment, not to the original. This is useful if you want to edit or crop an existing image without effecting the original To use, go to the Library tab and you will see a copy file link below each media (this will only appear in list view, see faq)

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C