Description
Missing Authorization vulnerability in termel Bulk Fields Editor bulk-user-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Fields Editor: from n/a through <= 1.8.0.
Published: 2025-04-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw in the termel Bulk Fields Editor plugin, allowing users with insufficient privileges to access and execute bulk edit functions for user or post metadata. The flaw can result in accidental or intentional data tampering, potentially leading to integrity violations across the site. The weakness is classified as a broken access control (CWE-862).

Affected Systems

The affected product is Bulk Fields Editor by termel, versions from the earliest listed up to and including 1.8.0. Users running any of these versions on their WordPress instances are susceptible.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity impact. The EPSS score, below 1%, suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s web interface, where an authenticated user may trigger the bulk edit UI. No additional constraints or prerequisites are specified in the CVE data beyond the presence of the plugin and insufficient access control.

Generated by OpenCVE AI on May 1, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bulk Fields Editor to a version newer than 1.8.0 to eliminate the vulnerability.
  • Configure WordPress role settings so that only administrators can access or use the Bulk Fields Editor plugin.
  • If the plugin is not required, remove or deactivate it entirely to prevent misuse.

Generated by OpenCVE AI on May 1, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9278 Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0. Missing Authorization vulnerability in termel Bulk Fields Editor bulk-user-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Fields Editor: from n/a through <= 1.8.0.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 01 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.
Title WordPress Bulk Fields Editor plugin <= 1.8.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.287Z

Reserved: 2025-04-01T13:19:14.439Z

Link: CVE-2025-31752

cve-icon Vulnrichment

Updated: 2025-04-01T20:32:49.753Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:11.690

Modified: 2026-04-23T15:28:13.037

Link: CVE-2025-31752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses