Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 06 Oct 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Tue, 06 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. | |
| Title | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-06T10:41:53.747Z
Reserved: 2026-09-21T09:26:45.343Z
Link: CVE-2026-94278
Updated: 2026-10-06T10:31:27.440Z
Status : Deferred
Published: 2026-10-06T07:17:00.080
Modified: 2026-10-06T15:18:12.170
Link: CVE-2026-94278
No data.
OpenCVE Enrichment
Updated: 2026-10-06T08:00:17Z
-
CWE-284
Improper Access Control