Missing Authorization in BEAR for WordPress Affects Product Manipulation
CVE-2023-4941

4.3MEDIUM

Key Information:

Summary

The BEAR for WordPress plugin is susceptible to a security flaw due to a missing capability check in the woobe_bulkoperations_swap function. This vulnerability permits authenticated users with subscriber level access or higher to execute unauthorized actions, specifically enabling them to manipulate product data. This lack of authorization controls could lead to unauthorized changes in product information, potentially compromising the integrity of an online store.

Affected Version(s)

BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net * <= 1.1.3.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marco Wotschka
.