CVE-2026-57320: WordPress BEAR plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability
Published Jun 29, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
Affected Software
1 affected component
WordPress BEAR Plugin<=1.1.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BEAR Pluginto a version that resolves this vulnerability.Fixed in 1.1.9
Event History
Jun 29, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57320?
CVE-2026-57320 has a severity rating of 7.1, indicating a high level of risk.
2
What type of vulnerability is CVE-2026-57320?
CVE-2026-57320 is an unauthenticated Cross Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-57320?
To mitigate CVE-2026-57320, update the WordPress BEAR plugin to version 1.1.9 or later.
4
Which versions of the WordPress BEAR plugin are affected by CVE-2026-57320?
CVE-2026-57320 affects all versions of the WordPress BEAR plugin up to and including version 1.1.8.
5
What risks are associated with CVE-2026-57320?
The risks associated with CVE-2026-57320 include potential execution of malicious scripts in a user's browser due to the XSS vulnerability.