The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
2023-10-20T08:15:12.673
2024-11-21T08:36:16.713
Modified
CVSSv3.1: 5.4 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | pluginus | bear_-_woocommerce_bulk_editor_and_products_manager_professional | ≤ 1.1.3.3 | Yes |