---
id: CVE-2026-94278
title: >-
  The File Media Renamer WordPress plugin through 1.3 does not verify that the
  requesting user is authorised to modify a given media attachment, allowing any
  user with file-upload privileges to rename attachments belonging to other
  users, …
summary: >-
  The File Media Renamer WordPress plugin through 1.3 does not verify that the
  requesting user is authorised to modify a given media attachment, allowing any
  user with file-upload privileges to rename attachments belonging to other
  users, …
severity: none
cwe:
  - CWE-284
product: File Media Renamer
affected:
  - file_media_renamer <= 1.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:17:00.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94278'
references:
  - url: 'https://wpscan.com/vulnerability/4967e8c2-ee27-4d26-955c-f7dfb6cd6942/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T06:48:36.102Z'
---

## Overview

The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
