Cross-site Scripting Vulnerability in Astra Bulk Edit by Brainstorm Force
CVE-2026-32431
6.5MEDIUM
What is CVE-2026-32431?
A vulnerability has been discovered in the Astra Bulk Edit plugin developed by Brainstorm Force, which allows the execution of malicious scripts in the context of the user's browser. This flaw arises from improper neutralization of input during web page generation, specifically affecting versions up to 1.2.10. As a result, attackers can exploit this weakness to perform DOM-Based Cross-site Scripting (XSS) attacks, potentially compromising user data and website integrity.
Affected Version(s)
Astra Bulk Edit 0 <= 1.2.10