Description
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
Published: 2026-09-12
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Taxonomy Term Modification
Action: Patch Immediately
AI Analysis

Impact

The BEAR Bulk Editor and Products Manager Professional for WooCommerce plugin version 1.2.2 and earlier fails to verify a CSRF nonce and to enforce user capability checks when updating taxonomy terms. This flaw, identified as CWE-352, allows an attacker to create a crafted URL that, when visited by a logged‑in privileged user, will modify arbitrary taxonomy entries such as product categories or tags without authorization, compromising the integrity of the e-commerce catalog.

Affected Systems

Any WordPress site that has installed the BEAR plugin earlier than version 1.2.2 is vulnerable. The plugin manages taxonomy terms used for WooCommerce products. The vulnerability permits unauthorized changes to taxonomy terms such as product categories or tags by a logged‑in privileged user, potentially affecting product visibility and search. Based on the plugin description, used in WooCommerce product listings.

Risk and Exploitability

The CVSS base score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the a logged‑in privileged user to visit a malicious link, after which the taxonomy terms can be altered without further authentication or detection.

Generated by OpenCVE AI on September 15, 2026 at 18:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the BEAR plugin to version 1.2.2 and capability gaps.
  • Restrict taxonomy editing permissions to the administrator role or to users with only the necessary capabilities.
  • Enable audit logging for taxonomy changes to detect and investigate unauthorized modifications.
  • Install a security plugin that validates CSRF nonces on taxonomy update requests, providing an additional safeguard.

Generated by OpenCVE AI on September 15, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-352

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
Title BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:32:25.040Z

Reserved: 2026-09-01T01:46:26.780Z

Link: CVE-2026-84023

cve-icon Vulnrichment

Updated: 2026-09-12T15:21:06.449Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:26.467

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-84023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)