CVE-2023-4940: BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobebulkoperationsswap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-4940.
What is the severity of CVE-2023-4940?
The severity of CVE-2023-4940 is medium with a score of 4.3.
Which software versions are affected by CVE-2023-4940?
Versions up to and including 1.1.3.3 of Pluginus Bear - Woocommerce Bulk Editor And Products Manager Professional for WordPress are affected by CVE-2023-4940.
How does CVE-2023-4940 affect the BEAR plugin for WordPress?
CVE-2023-4940 allows unauthenticated attackers to manipulate products via a forged request in the woobe_bulkoperations_swap function of the BEAR plugin for WordPress.
Is there a fix available for CVE-2023-4940?
Yes, there is a fix available for CVE-2023-4940. It is recommended to update to a version of Pluginus Bear - Woocommerce Bulk Editor And Products Manager Professional for WordPress that is higher than 1.1.3.3.