First published: Sat Mar 23 2024(Updated: )
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce | <=1.1.4 | |
WordPress BEAR Plugin | <=1.1.4 |
Update to 1.1.4.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24835 has been classified as a Missing Authorization vulnerability, which can potentially allow unauthorized access to sensitive functionalities.
To fix CVE-2024-24835, update the BEAR plugin to version 1.1.5 or later to ensure proper access controls are implemented.
CVE-2024-24835 affects realmag777 BEAR versions up to and including 1.1.4.
CVE-2024-24835 can lead to unauthorized users gaining access to perform actions they should not be allowed to, potentially compromising the security of your website.
While it's recommended to update, without an update, implement strict user role management and limit access to the plugin settings as a temporary measure.