CVE-2023-4920: BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobesaveoptions function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Additionally, input sanitization and escaping is insufficient resulting in the possibility of malicious script injection.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2023-4920?
The vulnerability CVE-2023-4920 is a Cross-Site Request Forgery (CSRF) vulnerability in the BEAR for WordPress plugin.
What is the severity of CVE-2023-4920?
The severity of CVE-2023-4920 is high with a CVSS score of 8.8.
How does CVE-2023-4920 affect the BEAR for WordPress plugin?
CVE-2023-4920 affects the BEAR for WordPress plugin versions up to and including 1.1.3.3.
How can an attacker exploit CVE-2023-4920?
An attacker can exploit CVE-2023-4920 by forging requests to modify the plugin's settings without proper validation.
Is there a fix available for CVE-2023-4920?
Yes, a fix is available for CVE-2023-4920. Update to a version of BEAR for WordPress higher than 1.1.3.3.