What the vulnerability does
01Description
Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Brainstorm Force Astra Bulk Edit.This issue affects Astra Bulk Edit: from n/a through 1.2.7.
Explanation of Vulnerability in Simple Terms
Astra Bulk Edit versions up to 1.2.7 lack proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify or delete site content without the appropriate permissions. The vulnerability affects data integrity and availability but does not expose sensitive information.
What an attacker can do
Modify or delete site content without having the required administrative permissions.
Potential impact on your site
Unauthorized users can alter or remove published content, pages, or posts through the bulk edit feature.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities