Description
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
Published: 2026-09-12
Score: 2.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via IDOR
Action: Apply Patch
AI Analysis

Impact

BEAR – Bulk Editor and Products Manager Professional for WooCommerce does not enforce ownership checks on several data handlers, allowing an authenticated user to request product data identified by a supplied product ID. This flaw lets users who read other download URLs and private metadata. The vulnerability exposes confidential commercial information and helps an attacker obtain downloadable assets or sensitive product attributes, resulting in information disclosure.

Affected Systems

The vulnerability affects installations of the BEAR plugin for WooCommerce running versions earlier than 1.2.2. No versions the fix. All WooCommerce sites that use the plugin before the specified release are susceptible.

Risk and Exploitability

a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting limited current abuse, but the only prerequisite—a logged-in user with limited product view rights—opens the attack surface to many merchants. Attackers could harvest protected download links or leak proprietary product data, potentially impacting confidentiality2.2, indicating a low severity impact.

Generated by OpenCVE AI on September 15, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the BEAR plugin to version 1.2.2.
  • If immediate upgrade is not possible, restrict product data endpoints to users who own the requested product until the patch is applied.
  • Audit product listings for exposed URLs or metadata and remove any that were unintentionally disclosed.

Generated by OpenCVE AI on September 15, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
Title BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:31:56.253Z

Reserved: 2026-09-01T01:46:33.443Z

Link: CVE-2026-84025

cve-icon Vulnrichment

Updated: 2026-09-12T15:20:26.930Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:26.700

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-84025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key