CSRF Vulnerability in Bulk Content Creator by luk3thomas
CVE-2025-27311
4.3MEDIUM
What is CVE-2025-27311?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Bulk Content Creator plugin by luk3thomas, which allows unauthorized actions to be performed on behalf ofauthenticated users. This can potentially lead to malicious actions being taken without the user's consent, compromising the integrity of the site. The vulnerability affects versions from n/a up to 1.2.1, emphasizing the need for immediate updates to secure your WordPress environment.
Affected Version(s)
Bulk Content Creator <= 1.2.1