Sceawere

Vulnerability Detail

CVE-2026-89283UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Post Password Reset Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
8h ago
Vendor
Unknown
Product
WP Posts Password Batch Manager
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-10-11T07:17:28.330Z",
  "pubdate": "2026-10-11T07:17:28.330Z",
  "executiveSummary": "The WP Posts Password Batch Manager WordPress plugin, specifically versions 1.1 and earlier, contains a critical security vulnerability involving the lack of access control validation.\nThis flaw is categorized as an Improper Access Control vulnerability, stemming from the absence of capability checks and nonce verification within a bulk post-password management handler.\nThe vulnerability allows remote, unauthenticated attackers to manipulate the password protection settings of all published posts on an affected WordPress installation.\nThe primary impact involves unauthorized disclosure of previously password-protected content or a total denial-of-service condition where legitimate users are locked out of posts via an attacker-defined password.\nBecause the vulnerable handler is always loaded during admin requests, no specific user privileges are required for successful exploitation.\nThe risk is considered critical, as it bypasses standard WordPress security mechanisms to permit arbitrary modification of sensitive content access controls without prior authentication.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure implementation of the bulk password management handler within the WP Posts Password Batch Manager plugin. The affected code fails to execute standard WordPress security routines, specifically the check_admin_referer() function for nonce verification and current_user_can() for capability validation.\nIn WordPress development, administrative handlers that modify post data must ensure that the request originates from a trusted source and is initiated by an authorized administrator. By omitting these checks, the plugin exposes an administrative endpoint directly to the public web interface.\nThe exploitation flow is as follows: An attacker identifies the vulnerable admin handler endpoint utilized by the plugin. Because the handler is loaded globally within the admin context, it processes requests even from unauthenticated sessions. The attacker crafts a malicious HTTP request—typically a POST request—targeting the bulk password update function. The payload contains the new password string to be applied to the target posts.\nUpon receiving the request, the plugin fails to verify the existence or validity of a security nonce, nor does it check if the requester possesses 'edit_posts' or 'manage_options' capabilities. Consequently, the backend script proceeds to iterate through the published posts and updates the password field in the database with the attacker's supplied value.\nThe post-exploitation impact is severe. An attacker can either set the passwords to a known string to bypass existing protections and view private content, or apply a randomized password across all posts to lock out site administrators and legitimate users. This creates an immediate impact on site availability and data confidentiality. The vulnerability is entirely network-exploitable, requiring only the ability to reach the site's administrative interface, which is standard in most WordPress configurations."
}
CVE-2026-89283: Unauthenticated Post Password Reset Vulnerability (HIGH Severity, CVSS: 8.6) | Sceawere