Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-15727 - WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter

CVE ID :CVE-2026-15727 Published : July 16, 2026, 8:26 a. m. | 32 minutes ago Description :The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.

4. 2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.

Originally reported by CVE Recent
0 comments

0 comments

Posting as FierceIbex132
0/1000

No comments yet. Be the first to start the discussion.