Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/media-file-renamer/#developers | Release Notes Third Party Advisory |
https://patchstack.com/database/vulnerability/media-file-renamer/wordpress-media-file-renamer-plugin-5-1-9-multiple-cross-site-request-forgery-csrf-vulnerabilities | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-10-04 10:15
Updated : 2021-10-08 10:31
NVD link : CVE-2021-36850
Mitre link : CVE-2021-36850
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
meowapps
- media_file_renamer_-_auto_\&_manual_rename