Access violation vulnerability in Easy Media Replace 0.1.3

The Easy Media Replace plugin for WordPress has a security vulnerability that could allow someone with access to the website (like an author) to delete files located on the server. This is possible because of a flaw in the plugin’s replace function which can be found in all versions up to 0.1.3. The person can only delete files that are of the same type as the ones they can upload.

Detected in:

Easy Media Replace fixed vulnerable versions: >= * <= 0.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.