plugin

Astra Bulk Edit Vulnerabilities

4 known security issues reported for the Astra Bulk Edit WordPress plugin. Most recent disclosed Mar 13, 2026.

2 medium

Running Astra Bulk Edit on your site? Check whether your installed version is affected.

Scan your site free

Astra Bulk Edit [astra-bulk-edit] <= 1.2.10 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Bulk Edit astra-bulk-edit allows DOM-Based XSS.This issue affects Astra Bulk Edit: from n/a through <= 1.2.10.

Affected:
up to 1.2.10
Fix:
No patched version reported
Disclosed:
Mar 13, 2026

CVE-2026-32431 on NVD →

Astra Bulk Edit <= 1.2.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Astra Bulk Edit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Mar 1, 2026

CVE-2026-32431 on NVD →

Astra Bulk Edit [astra-bulk-edit] < 1.2.8

unknown

[en] Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Jun 19, 2024

CVE-2023-44148 on NVD →

Astra Bulk Edit <= 1.2.7 - Missing Authorization

medium

The Astra Bulk Edit plugin for WordPress is vulnerable to unauthorized missing authorization due to a missing capability check on the save_post_bulk_edit function in versions up to, and including, 1.2.7. This makes it possible for attackers with contributor-level access or higher to bulk edit posts.

CVSS:
4.3
Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Sep 22, 2023

CVE-2023-44148 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database