Bulk Delete <= 5.5.3 - Missing Authorization

2016-03-03 00:00
Panagiotis Vagenas

Strategic Overview

Status
Patched in 5.5.4
Affected PluginBulk Delete
Affected Version< 5.5.4
CVSS5.4Medium
CVEN/A
View all Bulk Delete vulnerabilities

Vulnerability Overview

The Bulk Delete plugin for WordPress is vulnerable to missing authorization due to missing capability checks on several functions in versions before 5.5.4. This makes it possible for authenticated attackers to perform restricted actions which could lead to the arbitrary deletion of site content including pages, posts and users.

Technical Analysis

REMEDIATION: Update to version 5.5.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C