Vulnerabilities > CVE-2021-24816 - Unspecified vulnerability in Phoenix Media Rename Project Phoenix Media Rename

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
phoenix-media-rename-project

Summary

The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.

Vulnerable Configurations

Part Description Count
Application
Phoenix_Media_Rename_Project
49