Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-101476
HistoryNov 10, 2021 - 12:00 a.m.

WordPress Plugin Access Control Error Vulnerability (CNVD-2021-101476)

2021-11-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
8

0.001 Low

EPSS

Percentile

25.0%

WordPress is the Wordpress Foundation’s set of blogging platforms developed using the PHP language. The platform supports setting up personal blog sites on servers with PHP and MySQL. WordPress Plugin is a WordPress open source application plugin. access control error vulnerability in Wordpress Plugin Phoenix Media Rename, the vulnerability stems from not doing permission validation on Ajax operations for the renaming feature. An attacker could rename files that do not belong to them through a user with author rights.

CPENameOperatorVersion
wordpress phoenix media renamelt3.4.4

0.001 Low

EPSS

Percentile

25.0%