PT-2026-51670 · Seo Tools · Bulk Seo Image

Nishida Azuka

·

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-11997

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validation on the plugin's settings page handler BulkSeoImage(), which dispatches to launchbulk() / BulkSeoImageGo() whenever the request contains $ POST['bulkseoimage']. No wp nonce field() is emitted in the form and no check admin referer()/wp verify nonce() is performed before bulk-overwriting the wp attachment image alt post meta for every image attached to every published post and/or page. This makes it possible for unauthenticated attackers to bulk-overwrite image ALT-text metadata across the site via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11997

Affected Products

Bulk Seo Image