Impact
The BEAR Bulk Editor and Products Manager Professional for WooCommerce plugin version 1.2.2 and earlier fails to verify a CSRF nonce and to enforce user capability checks when updating taxonomy terms. This flaw, identified as CWE-352, allows an attacker to create a crafted URL that, when visited by a logged‑in privileged user, will modify arbitrary taxonomy entries such as product categories or tags without authorization, compromising the integrity of the e-commerce catalog.
Affected Systems
Any WordPress site that has installed the BEAR plugin earlier than version 1.2.2 is vulnerable. The plugin manages taxonomy terms used for WooCommerce products. The vulnerability permits unauthorized changes to taxonomy terms such as product categories or tags by a logged‑in privileged user, potentially affecting product visibility and search. Based on the plugin description, used in WooCommerce product listings.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the a logged‑in privileged user to visit a malicious link, after which the taxonomy terms can be altered without further authentication or detection.
OpenCVE Enrichment