Missing Authorization in BEAR for WordPress Affects Product Manipulation
CVE-2023-4941
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2023-4941?
The BEAR for WordPress plugin is susceptible to a security flaw due to a missing capability check in the woobe_bulkoperations_swap function. This vulnerability permits authenticated users with subscriber level access or higher to execute unauthorized actions, specifically enabling them to manipulate product data. This lack of authorization controls could lead to unauthorized changes in product information, potentially compromising the integrity of an online store.
Affected Version(s)
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net * <= 1.1.3.3