WordPress Plugin Vulnerabilities

Media File Renamer - Auto & Manual Rename < 5.2.7 - Media Title/Filename/Locking State Update via CSRF

Description

The plugin does not have CSRF in place, which could allow attacker to make a logged in admin change arbitrary uploaded media title, filename, as well as locking state via a CSRF attack

Notes:
- We were unable to reproduce the issue from an attacker point of view, the endpoints are expecting JSON data, with the correct Content-Type header, but CORS prevent doing that from another origin (cookies won't be included)
- Original report mentions the issue being fixed in 5.2.0, however proper fixes are in 5.2.7

Proof of Concept

Affects Plugins

Fixed in 5.2.7

References

Classification

Miscellaneous

Original Researcher
Ngo Van Thien
Verified
Yes

Timeline

Publicly Published
2021-09-04 (about 4 years ago)
Added
2021-10-05 (about 4 years ago)
Last Updated
2022-04-12 (about 3 years ago)

Other