The Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.Creditsdc11WPScanReferenceshttps://wpscan.com/vulnerability/b0239208-1e23-4774-9b8c-9611704a07a0