← WordPress Vulnerabilities
WordPress security by component

wp-bulk-delete

wp-bulk-delete is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 16, 2026; the highest CVE/CNA score is 7.1.

Plugin slug: wp-bulk-delete

CVE-2026-15727: WP Bulk Delete user-role filter permits SQL injection

WP Bulk Delete 1.4.2 and earlier places delete_user_roles into a database query without sufficient preparation. An authenticated administrator can inject additional SQL and extract information from the WordPress database; the administrator prerequisite limits exposure but does not make a compromised admin session safe.

PublishedJul 16, 2026
Known safe version> 1.4.2
Safe version
Jul 16, 2026 CVE-2026-15727
WP Bulk Delete user-role filter permits SQL injection
WP Bulk Delete 1.4.2 and earlier places delete_user_roles into a database query without sufficient preparation. An authenticated administrator can inject additional SQL and extract information from the WordPress database; the administrator prerequisite limits exposure but does not make a compromised admin session safe.
> 1.4.2
CVE4.9
NVDPending
Aug 27, 2025 CVE-2025-58192
WP Bulk Delete: A security weakness
WP Bulk Delete is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD5.4
Oct 06, 2024 CVE-2024-47352
WP Bulk Delete: Cross-site scripting
WP Bulk Delete is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending