CVE-2026-94278 PUBLISHED

File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat

Assigner: WPScan
Reserved: 21.09.2026 Published: 06.10.2026 Updated: 06.10.2026

The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.

Product Status

Vendor Unknown
Product File Media Renamer
Versions Default: unknown
  • affected from 0 to 1.3 (incl.)

Credits

  • Sebastian Riveros finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE