Unauthorized Password Management in WP Posts Password Batch Manager Plugin
CVE-2026-89283
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2026
Badges
What is CVE-2026-89283?
The WP Posts Password Batch Manager plugin for WordPress versions up to 1.1 contains a significant flaw that allows attackers to exploit its bulk post-password feature. The plugin lacks essential capability and nonce checks, enabling unauthenticated users to reset or overwrite the passwords of all published posts. This vulnerability can lead to a complete exposure of password-protected content or potentially lock users out by setting arbitrary passwords on posts. As a result, sensitive content may become accessible to unauthorized individuals, or legitimate users may be unable to access their own information.
Affected Version(s)
WP Posts Password Batch Manager 0 <= 1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.