CVE-2023-4943: BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobebulkoperationsvisibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability associated with CVE-2023-4943?
The vulnerability associated with CVE-2023-4943 is Missing Authorization in the BEAR for WordPress plugin.
What is the severity of CVE-2023-4943?
The severity of CVE-2023-4943 is medium with a severity score of 4.3.
How can an attacker exploit CVE-2023-4943?
An authenticated attacker (subscriber or higher) can exploit CVE-2023-4943 by manipulating products in the BEAR for WordPress plugin.
What software versions are affected by CVE-2023-4943?
Versions up to and including 1.1.3.3 of the BEAR for WordPress plugin are affected by CVE-2023-4943.
Is there a fix available for CVE-2023-4943?
Yes, upgrading to a version beyond 1.1.3.3 of the BEAR for WordPress plugin will fix CVE-2023-4943.