Sceawere
Vulnerability Detail
CVE-2026-89283UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Post Password Reset Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- WP Posts Password Batch Manager
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-11T07:17:28.330Z",
"pubdate": "2026-10-11T07:17:28.330Z",
"executiveSummary": "The WP Posts Password Batch Manager WordPress plugin, specifically versions 1.1 and earlier, contains a critical security vulnerability involving the lack of access control validation.\nThis flaw is categorized as an Improper Access Control vulnerability, stemming from the absence of capability checks and nonce verification within a bulk post-password management handler.\nThe vulnerability allows remote, unauthenticated attackers to manipulate the password protection settings of all published posts on an affected WordPress installation.\nThe primary impact involves unauthorized disclosure of previously password-protected content or a total denial-of-service condition where legitimate users are locked out of posts via an attacker-defined password.\nBecause the vulnerable handler is always loaded during admin requests, no specific user privileges are required for successful exploitation.\nThe risk is considered critical, as it bypasses standard WordPress security mechanisms to permit arbitrary modification of sensitive content access controls without prior authentication.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure implementation of the bulk password management handler within the WP Posts Password Batch Manager plugin. The affected code fails to execute standard WordPress security routines, specifically the check_admin_referer() function for nonce verification and current_user_can() for capability validation.\nIn WordPress development, administrative handlers that modify post data must ensure that the request originates from a trusted source and is initiated by an authorized administrator. By omitting these checks, the plugin exposes an administrative endpoint directly to the public web interface.\nThe exploitation flow is as follows: An attacker identifies the vulnerable admin handler endpoint utilized by the plugin. Because the handler is loaded globally within the admin context, it processes requests even from unauthenticated sessions. The attacker crafts a malicious HTTP request—typically a POST request—targeting the bulk password update function. The payload contains the new password string to be applied to the target posts.\nUpon receiving the request, the plugin fails to verify the existence or validity of a security nonce, nor does it check if the requester possesses 'edit_posts' or 'manage_options' capabilities. Consequently, the backend script proceeds to iterate through the published posts and updates the password field in the database with the attacker's supplied value.\nThe post-exploitation impact is severe. An attacker can either set the passwords to a known string to bypass existing protections and view private content, or apply a randomized password across all posts to lock out site administrators and legitimate users. This creates an immediate impact on site availability and data confidentiality. The vulnerability is entirely network-exploitable, requiring only the ability to reach the site's administrative interface, which is standard in most WordPress configurations."
}