plugin

Bulk Edit Post Titles Vulnerabilities

2 known security issues reported for the Bulk Edit Post Titles WordPress plugin. Most recent disclosed Feb 26, 2024.

2 medium

Running Bulk Edit Post Titles on your site? Check whether your installed version is affected.

Scan your site free

Bulk Edit Post Titles <= 5.0.0 - Missing Authorization via bulkUpdatePostTitles

medium

The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bulkUpdatePostTitles function in all versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with subscriber access and above, to modify the titles...

CVSS:
4.3
Affected:
up to 5.0.0
Fix:
No patched version reported
Disclosed:
Feb 26, 2024

CVE-2024-0369 on NVD →

Bulk Edit Post Titles <= 5.0.0 - Missing Authorization

medium

The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 5.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action

CVSS:
4.3
Affected:
up to 5.0.0
Fix:
No patched version reported
Disclosed:
Dec 4, 2023

CVE-2023-49754 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database