Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 11 Oct 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Sun, 11 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Sun, 11 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 |
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password. | |
| Title | WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-11T11:32:41.577Z
Reserved: 2026-09-11T12:03:53.092Z
Link: CVE-2026-89283
Updated: 2026-10-11T11:15:50.724Z
Status : Received
Published: 2026-10-11T07:17:28.330
Modified: 2026-10-11T12:17:27.187
Link: CVE-2026-89283
No data.
OpenCVE Enrichment
Updated: 2026-10-11T17:30:17Z
-
CWE-862
Missing Authorization