CVE-2026-89283
WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.
| Vendor | unknown |
| Product | wp posts password batch manager |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp posts password batch manager
Be the first to know when new unknown vulnerabilities affecting unknown wp posts password batch manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Posts Password Batch Manager
0 โค 1.1
References
Credits
Naoki Kawahigashi WPScan