Impact
The Set Bulk Post Categories plugin contains a missing nonce check in its bulk category update feature, enabling a Cross‑Site Request Forgery (CSRF) flaw. An attacker can craft a forged request which, if an administrator visits a malicious link, will execute the bulk update and re‑categorize arbitrary posts. This problem is identified as CWE‑352 and compromises the integrity of site content.
Affected Systems
Sauravrox Set Bulk Post Categories plugin for WordPress, versions 1.1 and below.
Risk and Exploitability
The CVSS score of 4.3 reflects low severity, while the EPSS score of <1% indicates a low probability of exploitation at present. The vulnerability does not appear in the CISA KEV catalog. Likely exploitation requires a social‑engineering step where an attacker forces an authenticated administrator to click a crafted link, thereby sending the forged request with adequate privileges.
OpenCVE Enrichment