CVE-2026-2732Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewController::load' function in all versions up to, and including, 4.1.7. This makes it possible for authenticated attackers, with Author-level access and above, to replace any attachment with a removed background attachment.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 203-0403-05
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-051
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2732 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2732 #CVE-2026-2732 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/InUKdnNatB

    Post summary

    The tweet announces a new CVE (CVE‑2026‑2732) with medium severity affecting WordPress, providing a link to the NVD detail page.

    0000040
    65 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2732 The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewControl… https://www.cve.org/CVERecord?id=CVE-2026-2732 ----- Traducción: CVE-2026-2732 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2732, noting that the Enable Media Replace plugin for WordPress allows unauthorized data modification due to an improper capability check.

    0000028
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2732 The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'RemoveBackGroundViewControl… https://www.cve.org/CVERecord?id=CVE-2026-2732

    Post summary

    The Enable Media Replace plugin for WordPress is affected by CVE-2026-2732, which allows unauthorized data modification because of an improper capability check.

    00000311
    56.6K followersView on X

Explore more