CVE-2026-89283
Received Received - Intake

Unauthenticated Post Password Reset in WP Posts Password Batch Manager

Vulnerability report for CVE-2026-89283, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The WP Posts Password Batch Manager WordPress plugin through 1.1 does not perform any capability or nonce check on a bulk post-password action that runs on an always-loaded admin handler, allowing unauthenticated attackers to reset or overwrite the password of every published post, disclosing password-protected content or locking all posts behind an attacker-chosen password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown WP Posts Password Batch Manager 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin WP Posts Password Batch Manager version 1.1 or below. It allows unauthenticated attackers to reset or overwrite passwords for all published posts without proper checks. The flaw occurs because the bulk post-password action runs on an always-loaded admin handler without capability or nonce verification.

Detection Guidance

Check if the WP Posts Password Batch Manager plugin version 1.1 or below is installed on your WordPress site. Look for unusual password changes on published posts or unexpected admin actions.

Impact Analysis

Attackers could disclose password-protected content by resetting post passwords or lock all posts behind an attacker-chosen password, making content inaccessible to legitimate users. This could disrupt website functionality and expose sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to password-protected content, potentially exposing sensitive data. This may violate GDPR's data protection principles if personal data is disclosed, and HIPAA's confidentiality requirements if protected health information is compromised.

Mitigation Strategies

Immediately update the WP Posts Password Batch Manager plugin to the latest version if available. If no update exists, consider disabling or removing the plugin until a patch is released. Monitor posts for unauthorized password changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89283. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart