๐Ÿ” CVE Alert

CVE-2026-94278

MEDIUM 5.5

File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.

Vendor unknown
Product file media renamer
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown file media renamer

Be the first to know when new medium vulnerabilities affecting unknown file media renamer are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / File Media Renamer
0 โ‰ค 1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4967e8c2-ee27-4d26-955c-f7dfb6cd6942/

Credits

Sebastian Riveros WPScan