Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Phoenix Media Rename Project Subscribe
Filtered by product Phoenix Media Rename
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24816 1 Phoenix Media Rename Project 1 Phoenix Media Rename 2021-11-09 4.0 MEDIUM 4.3 MEDIUM
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.