CVE-2026-94278
Received Received - Intake

File Media Renamer WordPress Plugin Unauthorised Media Renaming

Vulnerability report for CVE-2026-94278, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: WPScan

Description

The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown File Media Renamer 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The File Media Renamer WordPress plugin through version 1.3 has a vulnerability where it does not check if a user is authorized to modify a media attachment. This allows any user with file-upload privileges to rename attachments belonging to other users, including administrators, and potentially corrupt site data that uses the old file paths.

Detection Guidance

Check if the File Media Renamer plugin version 1.3 or below is installed on your WordPress site. Review media attachment logs for unauthorized renaming events. Inspect file paths in site data for inconsistencies.

Impact Analysis

This vulnerability could allow unauthorized users to rename files, disrupt site functionality, and corrupt data that relies on the original file paths. It may also lead to confusion or misinformation if files are renamed maliciously.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized users to rename or corrupt media files, which may include sensitive data. Unauthorized file renaming could lead to data integrity issues or unauthorized access to protected information, violating principles of data protection and confidentiality required by these regulations.

Mitigation Strategies

Immediately update the File Media Renamer plugin to the latest version if available. If no update exists, consider disabling the plugin until a patch is released. Restrict file-upload privileges to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94278. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart