CVE-2025-26775: WordPress BEAR Plugin <= 1.1.4.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR woo-bulk-editor allows Stored XSS.This issue affects BEAR: from n/a through <= 1.1.4.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26775?
CVE-2025-26775 is classified as a high severity vulnerability due to its potential for Stored XSS attacks.
How do I fix CVE-2025-26775?
To fix CVE-2025-26775, upgrade RealMag777 BEAR or WordPress BEAR Plugin to versions later than 1.1.4.4.
What versions are affected by CVE-2025-26775?
CVE-2025-26775 affects RealMag777 BEAR and WordPress BEAR Plugin versions up to and including 1.1.4.4.
Where can CVE-2025-26775 be exploited?
CVE-2025-26775 can be exploited in any web application utilizing the affected versions of the RealMag777 BEAR or WordPress BEAR Plugin.
What type of vulnerability is CVE-2025-26775?
CVE-2025-26775 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as a Cross-Site Scripting (XSS) vulnerability.