Authorization Flaw in BEAR for WordPress Affects Product Manipulation
CVE-2023-4943
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 October 2023
What is CVE-2023-4943?
The BEAR for WordPress plugin is affected by a missing capability check in the woobe_bulkoperations_visibility function, allowing authenticated users with subscriber or higher roles to bypass authorization controls. This vulnerability can lead to unauthorized manipulation of product listings within the plugin, posing significant risks to website integrity and user trust.
Affected Version(s)
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net * <= 1.1.3.3