Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
References
Link | Resource |
---|---|
https://patchstack.com/database/vulnerability/media-file-renamer/wordpress-media-file-renamer-plugin-5-1-9-multiple-cross-site-request-forgery-csrf-vulnerabilities | Third Party Advisory |
https://wordpress.org/plugins/media-file-renamer/#developers | Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Patchstack
Published: 2021-04-08T00:00:00
Updated: 2021-10-04T16:57:04
Reserved: 2021-07-19T00:00:00
Link: CVE-2021-36850
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-10-04T17:15:07.790
Modified: 2021-10-08T17:31:52.240
Link: CVE-2021-36850
JSON object: View
Redhat Information
No data.
CWE