Bulk Term Editor
Bulk Term Editor has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Bulk Term Editor has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Skalucy. Bulk Term Editor is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2025-39512Bulk Term Editor <= 1.1.4 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

Bulk Term Editor
Author
Yuya Hoshino
How it works: Click ‘Tools > Bulk Term Editor’. Select a taxonomy. If you selected a taxonomy which has terms, it will read those into the field. Get your data ready. Prepare your data by spreadsheet such as Excel. If you selected a taxonomy which has terms at the step 2, it’s easy to copy that data into the spreadsheet. Copy the cells. You may copy all lines, but the more lines there are, the more times spends. Copying the minimum necessary lines is the best, but safer to copy all lines. Paste to this plugin. Paste it into the ‘Term’ field of this plugin. Execute. Clicking the ‘Edit’ button executes it. Delete Entering a ‘*’ in beginning of line will delete. Change the term slug Entering a ‘>New slug’ after the term slug will change the term slug. Add When the term slug is a blank or new, add.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C