WordPress Plugin Vulnerabilities

File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat

Description

The plugin does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.

Proof of Concept

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE

Miscellaneous

Original Researcher
Sebastian Riveros
Submitter
Sebastian Riveros
Verified
Yes

Timeline

Publicly Published
2026-10-03 (about 2 days ago)
Added
2026-09-26 (about 9 days ago)
Last Updated
2026-09-26 (about 9 days ago)

Other