Bulk Delete <= 5.5.3 - Missing Authorization
2016-03-03 00:00
Panagiotis VagenasStrategic Overview
Vulnerability Overview
The Bulk Delete plugin for WordPress is vulnerable to missing authorization due to missing capability checks on several functions in versions before 5.5.4. This makes it possible for authenticated attackers to perform restricted actions which could lead to the arbitrary deletion of site content including pages, posts and users.
Technical Analysis
REMEDIATION: Update to version 5.5.4, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C