CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress.
CVE
CVE-2021-24816
Severity
MEDIUM
CVSS
4.3
EPSS
0.65%
WordPress
Original NVD Description
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.