Authorization Flaw in BEAR for WordPress Affects Product Manipulation
CVE-2023-4943
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 20 October 2023
Summary
The BEAR for WordPress plugin is affected by a missing capability check in the woobe_bulkoperations_visibility function, allowing authenticated users with subscriber or higher roles to bypass authorization controls. This vulnerability can lead to unauthorized manipulation of product listings within the plugin, posing significant risks to website integrity and user trust.
Affected Version(s)
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net * <= 1.1.3.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka