The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation |
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-10-18T07:31:17.079Z
Updated: 2026-04-08T17:20:33.324Z
Reserved: 2023-09-13T13:58:21.872Z
Link: CVE-2023-4938
Updated: 2024-08-02T07:44:52.693Z
Status : Modified
Published: 2023-10-18T08:15:08.207
Modified: 2026-04-08T19:18:40.193
Link: CVE-2023-4938
No data.