WordPress Plugin Vulnerabilities

WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite

Description

The plugin does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-09 (about 1 day ago)

Other