CVE-2026-94278
File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.
| Vendor | unknown |
| Product | file media renamer |
| Published | Oct 6, 2026 |
| Last Updated | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown file media renamer
Be the first to know when new medium vulnerabilities affecting unknown file media renamer are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / File Media Renamer
0 โค 1.3
References
Credits
Sebastian Riveros WPScan