Unauthorized Access to Post Editing Functionality in Bulk Posts Editing For WordPress Plugin

CVE-2024-4199
4.3MEDIUM

Key Information

Vendor
Ithemelandco
Status
Bulk Posts Editing For WordPress
Vendor
Published:
15 May 2024

Summary

The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke their corresponding functions. This may lead to post creation and duplication, post content retrieval, post taxonomy manipulation.

Affected Version(s)

Bulk Posts Editing For WordPress <= 4.2.3

CVSS V3.1

Score:
4.3
Severity:
MEDIUM

Timeline

  • Vulnerability published.

  • Disclosed

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Benedictus Jovan
.