Impact
This vulnerability is a missing authorization flaw in the termel Bulk Fields Editor plugin, allowing users with insufficient privileges to access and execute bulk edit functions for user or post metadata. The flaw can result in accidental or intentional data tampering, potentially leading to integrity violations across the site. The weakness is classified as a broken access control (CWE-862).
Affected Systems
The affected product is Bulk Fields Editor by termel, versions from the earliest listed up to and including 1.8.0. Users running any of these versions on their WordPress instances are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity impact. The EPSS score, below 1%, suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s web interface, where an authenticated user may trigger the bulk edit UI. No additional constraints or prerequisites are specified in the CVE data beyond the presence of the plugin and insufficient access control.
OpenCVE Enrichment
EUVD