Media File Renamer <= 5.7.7 - Authenticated(Administrator+) Remote Code Execution
medium
The Media File Renamer: Rename Files (Manual, Auto & AI) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.7.7. This makes it possible for authenticated attackers, with administrator access and above, to execute code on the server by renaming files containing PHP code.
- CVSS:
- 6.6
- Affected:
- up to 5.7.7
- Fixed in:
- 5.7.8
- Disclosed:
- Dec 26, 2023
CVE-2023-50897 on NVD →
Media File Renamer: Rename for better SEO (AI-Powered) [media-file-renamer] < 5.7.0
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files (Manual, Auto & AI).This issue affects Media File Renamer: Rename Files (Manual, Auto & AI): from n/a through 5.6.9.
- Affected:
- up to 5.7.0
- Fixed in:
- 5.7.0
- Disclosed:
- Dec 19, 2023
CVE-2023-44991 on NVD →
Media File Renamer <= 5.6.9 - Sensitive Information Exposure via Log File
medium
The Media File Renamer: Rename Files (Manual, Auto & AI) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.9 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including file upload events and paths.
- CVSS:
- 5.3
- Affected:
- up to 5.6.9
- Fixed in:
- 5.7.0
- Disclosed:
- Nov 28, 2023
CVE-2023-44991 on NVD →
Media File Renamer: Rename for better SEO (AI-Powered) [media-file-renamer] < 5.2.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.1.9). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.7
- Disclosed:
- Oct 4, 2021
CVE-2021-36850 on NVD →
Media File Renamer – Auto & Manual Rename <= 5.2.5 - Cross-Site Request Forgery
high
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions <= 5.2.5). Affected parameters "post_title", "filename", "lock". This allows changing the uploaded media title, media file name, and media locking state.
- CVSS:
- 8.8
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Apr 8, 2021
CVE-2021-36850 on NVD →
Media File Renamer: Rename for better SEO (AI-Powered) [media-file-renamer] < 2.2.2
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated users with permissions to add media or edit media to inject arb...
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.2
- Disclosed:
- Mar 3, 2014
CVE-2014-2040 on NVD →
Media File Renamer < 1.9.4 - Stored Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated users with permissions to add media or edit media to inject arbitrar...
- CVSS:
- 6.4
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Jan 31, 2014
CVE-2014-2040 on NVD →
Media File Renamer – Auto & Manual Rename <= 5.2.5 - Missing Authorization Checks
high
The Media File Renamer – Auto & Manual Rename plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'get_license' and 'set_license' API endpoints in versions up to, and including, 5.2.5. This makes it possible for authenticated Subscriber+ attackers to bypass otherwise rest...
- CVSS:
- 8.8
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Sep 3, 2012
Media File Renamer: Rename for better SEO (AI-Powered) [media-file-renamer] < 5.2.6
unknown
The Media File Renamer – Auto & Manual Rename plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'get_license' and 'set_license' API endpoints in versions up to, and including, 5.2.5. This makes it possible for authenticated Subscriber+ attackers to bypass otherwise rest...
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.6
- Disclosed:
- Sep 3, 2012
Media File Renamer: Rename for better SEO (AI-Powered) [media-file-renamer] < 5.7.8
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.7.8
- Fixed in:
- 5.7.8
CVE-2023-50897 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database