> case 'editattachment':
> check_admin_referer('update-post_' . $post_id);
Seems like you wouldn't be able to actually use this vulnerability without a valid nonce, so I don't see how you would trigger this unless you have some sort of malicious plugin also installed on the site . . ?