CVE-2023-33314: WordPress BEAR Plugin <= 1.1.3.1 is vulnerable to Cross Site Request Forgery (CSRF)
Published May 28, 2023
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
Affected Software
1 affected component
Pluginus Bear - Woocommerce Bulk Editor And Products Manager Professional Wordpress<1.1.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BEAR Pluginto a version that resolves this vulnerability.Fixed in 1.1.3.2
Event History
May 28, 2023
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-33314?
CVE-2023-33314 is a Cross-Site Request Forgery (CSRF) vulnerability in the realmag777 BEAR plugin version <= 1.1.3.1 for WordPress.
2
How severe is CVE-2023-33314?
CVE-2023-33314 has a severity score of 8.8, which is considered high.
3
How does CVE-2023-33314 affect the software?
CVE-2023-33314 affects the realmag777 BEAR plugin version <= 1.1.3.1 for WordPress.
4
Is there a fix for CVE-2023-33314?
Yes, updating the realmag777 BEAR plugin to version 1.1.3.2 or later fixes CVE-2023-33314.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-33314?
The CWE for CVE-2023-33314 is CWE-352 (Cross-Site Request Forgery).