Cross-Site Request Forgery Vulnerability in BEAR Plugin for WordPress
CVE-2026-84023
Currently unrated
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-84023?
A vulnerability in the BEAR WordPress plugin, prior to version 1.2.2, allows attackers to exploit a lack of CSRF nonce verification and user capability checks. This can enable unauthorized modifications of taxonomy terms when a privileged user is tricked into visiting a malicious page, potentially compromising the integrity of the site's content.
Affected Version(s)
BEAR 0 < 1.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.