Lucene search

K
wpvulndbWpvulndbWPVDB-ID:70B2AEC1-FE5A-4952-A7B9-703A11D825F1
HistoryNov 24, 2023 - 12:00 a.m.

Astra Bulk Edit < 1.2.8 - Missing Authorization

2023-11-2400:00:00
wpscan.com
21
astra bulk edit
wordpress
unauthorized access

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

20.0%

Description The Astra Bulk Edit plugin for WordPress is vulnerable to unauthorized missing authorization due to a missing capability check on the save_post_bulk_edit function in versions up to, and including, 1.2.7. This makes it possible for attackers with contributor-level access or higher to bulk edit posts.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

20.0%

Related for WPVDB-ID:70B2AEC1-FE5A-4952-A7B9-703A11D825F1