CVE-2026-89283: WP Posts Password Batch Manager <= 1.1 - Unauthenticated Bulk Post Password Rewrite
The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.
Affected Software
Event History
Frequently Asked Questions
Which plugin versions are affected?
WP Posts Password Batch Manager through version 1.1 is affected.
Does an attacker need a WordPress account or administrative privileges?
No. The bulk post-password action lacks both capability and nonce checks, so it can be triggered by an unauthenticated attacker.
What content can be changed through the vulnerable action?
An attacker can reset or overwrite the passwords of every published post. This can expose previously password-protected content or set attacker-chosen passwords that prevent normal access to posts.