Description
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 5.2.0 or higher version.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-23426 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state. |
References
History
Fri, 28 Mar 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:07:34.328Z
Reserved: 2021-07-19T00:00:00.000Z
Link: CVE-2021-36850
Updated: 2024-08-04T01:01:59.839Z
Status : Modified
Published: 2021-10-04T17:15:07.790
Modified: 2024-11-21T06:14:11.653
Link: CVE-2021-36850
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD