CVE-2023-4938: BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobebulkoperationsapplydefaultcombination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-4938?
CVE-2023-4938 is a vulnerability in the BEAR for WordPress plugin, allowing authenticated attackers to manipulate data.
What is the severity of CVE-2023-4938?
The severity of CVE-2023-4938 is medium with a CVSS score of 4.3.
How can authenticated attackers exploit CVE-2023-4938?
Authenticated attackers (subscriber or higher) can exploit CVE-2023-4938 to manipulate data.
Which versions of BEAR for WordPress are affected by CVE-2023-4938?
Versions up to and including 1.1.3.3 of BEAR for WordPress are affected by CVE-2023-4938.
How can I fix CVE-2023-4938?
To fix CVE-2023-4938, update BEAR for WordPress to a version higher than 1.1.3.3.