26 Mar 2025

ShortPixel Not Honest About Security Fix in Enable Media Replace

Yesterday, a new version of the WordPress plugin Enable Media Replace was released. The changelog for the new version was “Fix: A potential “Reflected Cross-Site Scripting” vulnerability has been patched, responsibly disclosed by the PatchStack team.” The developers claim that a “potential” vulnerability had been fixed turned out to not be true. As there was an actual vulnerability. We also found the code in the plugin still isn’t properly secured and we have notified the developer of that.


[Read more]

24 Feb 2023

Privilege Escalation Vulnerability in Enable Media Replace

The changelog for the latest version of the WordPress plugin Enable Media Replace makes no mention of fixing a security vulnerability, but there was a very minor one fixed. The changes being made in that version were flagged by our machine learning system, which tries to catch security fixes being made without it being disclosed.


[Read more]