Impact
BEAR – Bulk Editor and Products Manager Professional for WooCommerce does not enforce ownership checks on several data handlers, allowing an authenticated user to request product data identified by a supplied product ID. This flaw lets users who read other download URLs and private metadata. The vulnerability exposes confidential commercial information and helps an attacker obtain downloadable assets or sensitive product attributes, resulting in information disclosure.
Affected Systems
The vulnerability affects installations of the BEAR plugin for WooCommerce running versions earlier than 1.2.2. No versions the fix. All WooCommerce sites that use the plugin before the specified release are susceptible.
Risk and Exploitability
a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting limited current abuse, but the only prerequisite—a logged-in user with limited product view rights—opens the attack surface to many merchants. Attackers could harvest protected download links or leak proprietary product data, potentially impacting confidentiality2.2, indicating a low severity impact.
OpenCVE Enrichment