Missing Authorization in BEAR for WordPress Affects Product Manipulation
CVE-2023-4941
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 20 October 2023
Summary
The BEAR for WordPress plugin is susceptible to a security flaw due to a missing capability check in the woobe_bulkoperations_swap function. This vulnerability permits authenticated users with subscriber level access or higher to execute unauthorized actions, specifically enabling them to manipulate product data. This lack of authorization controls could lead to unauthorized changes in product information, potentially compromising the integrity of an online store.
Affected Version(s)
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net * <= 1.1.3.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka