CVE-2023-4924: BEAR <= 1.1.3.3 - Missing Authorization to Product Deletion
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobebulkoperationsdelete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4924?
CVE-2023-4924 is a vulnerability in the BEAR for WordPress plugin that allows authenticated attackers with subscriber access or higher to delete products.
What is the severity of CVE-2023-4924?
The severity of CVE-2023-4924 is medium with a CVSS score of 5.4.
How can an attacker exploit CVE-2023-4924?
An attacker with authenticated access can exploit CVE-2023-4924 by using the woobe_bulkoperations_delete function to delete products.
Is there a fix for CVE-2023-4924?
Yes, upgrading to a version higher than 1.1.3.3 of the BEAR for WordPress plugin fixes CVE-2023-4924.
Where can I find more information about CVE-2023-4924?
You can find more information about CVE-2023-4924 at the following references: [Reference 1](https://plugins.trac.wordpress.org/browser/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php#L344), [Reference 2](https://plugins.trac.wordpress.org/changeset/2970262/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php?contextall=1&old=2844667&old_path=%2Fwoo-bulk-editor%2Ftrunk%2Fext%2Fbulkoperations%2Fbulkoperations.php), [Reference 3](https://www.wordfence.com/threat-intel/vulnerabilities/id/7dfd0246-4265-4dde-8a1e-18b7042eae74?source=cve)