CVE-2023-50897: WordPress Media File Renamer plugin <= 5.7.7 - Arbitrary File Rename lead to RCE vulnerability
Published Jan 5, 2026
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media File Renamer: from n/a through 5.7.7.
Affected Software
2 affected components
Meow Apps Media File Renamer>=n/a, <=5.7.7
wordpress/media-file-renamer<=5.7.7
Remediation
Information
Update the WordPress Media File Renamer plugin to the latest available version (at least 5.7.8).
Event History
Jan 5, 2026
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-50897?
CVE-2023-50897 is considered a critical vulnerability due to its potential to allow the upload of malicious files.
2
How do I fix CVE-2023-50897?
To fix CVE-2023-50897, update Meow Apps Media File Renamer to version 5.7.8 or later.
3
What is CVE-2023-50897?
CVE-2023-50897 is an Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer.
4
Which versions are affected by CVE-2023-50897?
CVE-2023-50897 affects Meow Apps Media File Renamer versions from n/a through 5.7.7.
5
What types of files can be uploaded due to CVE-2023-50897?
Due to CVE-2023-50897, malicious files with dangerous types can be uploaded, leading to potential exploitation.