ZeroHour

CVE-2023-4924

CVSS 3.1
4.3 medium
EPSS
<1%p20
Published
()
Modified
Description

The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.

Vendors
pluginus
Products
bear - woocommerce bulk editor and products manager professional
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.