CVE-2021-36850: WordPress Media File Renamer – Auto & Manual Rename plugin <= 5.1.9 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "posttitle", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36850?
CVE-2021-36850 has a medium severity rating due to its potential for exploiting user input to change media attributes.
How do I fix CVE-2021-36850?
To fix CVE-2021-36850, update the Meowapps Media File Renamer plugin to version 5.1.10 or later.
What software is affected by CVE-2021-36850?
CVE-2021-36850 affects the Meowapps Media File Renamer plugin for WordPress versions 5.1.9 and earlier.
What type of vulnerability is CVE-2021-36850?
CVE-2021-36850 is a Cross-Site Request Forgery (CSRF) vulnerability.
What can be exploited in CVE-2021-36850?
CVE-2021-36850 can be exploited to change the uploaded media title, media file name, and media locking state.