Description
WordPress Plugin Bulk Delete is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Bulk Delete version 5.5.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.5.4 or latest
References
http://pvagenas.com/vulnerabilities/bulk-delete-privilege-escalation/
https://www.exploit-db.com/exploits/39521/
http://seclists.org/bugtraq/2016/Mar/17
https://packetstormsecurity.com/files/136067/WordPress-Bulk-Delete-5.5.3-Privilege-Escalation.html
Related Vulnerabilities
Oracle JRE CVE-2013-2473 Vulnerability (CVE-2013-2473)
MySQL CVE-2016-0667 Vulnerability (CVE-2016-0667)
Oracle Application Server CVE-2006-0288 Vulnerability (CVE-2006-0288)
WordPress 5.4.x Multiple Vulnerabilities (5.4 - 5.4.10)
WordPress Plugin Gallery Master-Responsive Photo Galleries & Albums Cross-Site Scripting (1.0.22)