First published: Mon Feb 17 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR allows Stored XSS. This issue affects BEAR: from n/a through 1.1.4.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce | <=1.1.4.4 | |
WordPress BEAR Plugin | <=1.1.4.4 |
Update the WordPress BEAR wordpress plugin to the latest available version (at least 1.1.4.5).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26775 is classified as a high severity vulnerability due to its potential for Stored XSS attacks.
To fix CVE-2025-26775, upgrade RealMag777 BEAR or WordPress BEAR Plugin to versions later than 1.1.4.4.
CVE-2025-26775 affects RealMag777 BEAR and WordPress BEAR Plugin versions up to and including 1.1.4.4.
CVE-2025-26775 can be exploited in any web application utilizing the affected versions of the RealMag777 BEAR or WordPress BEAR Plugin.
CVE-2025-26775 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as a Cross-Site Scripting (XSS) vulnerability.