ZeroHour

CVE-2021-24816

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p50
Published
()
Modified
Description

The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

Vendors
phoenix media rename project
Products
phoenix media rename
Ecosystems
WordPress
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.