CVE-2026-94278 Overview
CVE-2026-94278 is a broken access control vulnerability [CWE-284] in the File Media Renamer WordPress plugin through version 1.3. The plugin fails to verify that the requesting user owns the media attachment being modified. Any authenticated user with file-upload privileges can rename media attachments belonging to other users, including administrators. The rename operation also corrupts unrelated site data that referenced the previous file path.
Critical Impact
Low-privileged authors and contributors can tamper with administrator-owned media and break references to those files across stored site content.
Affected Products
- File Media Renamer WordPress plugin versions through 1.3
- WordPress sites allowing contributor, author, or higher roles with upload capability
- Any site content (posts, pages, metadata) referencing renamed attachments
Discovery Timeline
- 2026-10-06 - CVE-2026-94278 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-94278
Vulnerability Analysis
The File Media Renamer plugin exposes functionality to rename WordPress media attachments on the server and update the associated database records. The plugin omits an ownership check when processing rename requests. WordPress exposes a post_author field on every attachment that identifies the uploading user. The vulnerable code path does not compare the current user against this field before performing the rename.
An authenticated user with the upload_files capability can therefore submit a rename request targeting an attachment ID owned by another user. The plugin accepts the request, renames the underlying file on disk, and updates the attachment's post meta. Because WordPress and third-party plugins frequently store references to media URLs or file paths in post content, options, and custom tables, the rename cascades into stale references across the site.
Root Cause
The root cause is missing authorization enforcement on the attachment modification handler. The plugin relies solely on the WordPress capability check for upload_files and does not perform a per-object ownership or edit_post capability check against the target attachment ID. This maps directly to CWE-284 Improper Access Control.
Attack Vector
Exploitation requires an authenticated session with upload privileges, which corresponds to the Author or Contributor role on many WordPress deployments. The attacker enumerates attachment IDs belonging to administrators or other privileged users and issues the plugin's rename action against those IDs. No user interaction from the victim is required. The resulting integrity impact includes modified file names, broken image references in published posts, and corrupted plugin or theme data that stored the original path.
No public proof-of-concept exploit is listed in the referenced advisory. See the WPScan Vulnerability Report for technical details.
Detection Methods for CVE-2026-94278
Indicators of Compromise
- Unexpected renames in the wp-content/uploads/ directory tree where file modification timestamps do not align with upload events
- WordPress postmeta entries where _wp_attached_file has changed without a corresponding administrator action in the audit log
- Broken media references (404s on image URLs) in previously published posts authored by administrators
- Plugin or theme data referencing filenames that no longer exist on disk
Detection Strategies
- Review web server access logs for POST requests to File Media Renamer plugin endpoints originating from non-administrator user sessions
- Correlate attachment modification events with the post_author of the attachment and the acting user; mismatches indicate exploitation
- Monitor WordPress audit logs for rename actions performed against attachments the acting user did not upload
Monitoring Recommendations
- Enable file integrity monitoring on the wp-content/uploads/ directory and alert on rename operations outside maintenance windows
- Deploy a WordPress activity logging plugin and generate alerts when a user modifies media owned by another account
- Track HTTP referers and session identifiers associated with plugin administrative actions to attribute changes to specific accounts
How to Mitigate CVE-2026-94278
Immediate Actions Required
- Deactivate the File Media Renamer plugin until a patched version is confirmed available
- Audit WordPress user accounts and remove unnecessary Author, Editor, or Contributor privileges
- Restore media filenames and references from backup if unauthorized rename activity is detected
Patch Information
No fixed version is referenced in the published advisory. The vulnerability affects File Media Renamer through version 1.3. Monitor the WPScan Vulnerability Report and the plugin repository for an update that introduces an ownership check on the rename handler.
Workarounds
- Remove the plugin entirely if a patched release is unavailable and the functionality is not operationally required
- Restrict upload privileges to trusted administrators and demote standard content contributors to roles without the upload_files capability
- Apply a Web Application Firewall rule that blocks the plugin's rename action when the requesting user does not match the attachment's post_author
# Disable the plugin via WP-CLI pending a patched release
wp plugin deactivate file-media-renamer
# Audit users with upload_files capability
wp user list --field=user_login --role=author,editor,contributor
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.