cleantalk
Vulnerabilities and Security Researches

Enable Media Replace, CVE-2026-2732

CVE, Research URL

CVE-2026-2732

Application

Enable Media Replace

Published on
Mar 04, 2026
Research Description
The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.
Affected versions
max 4.1.8.
Status
vulnerable