CVE-2026-84023: BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRF
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BEAR - Bulk Editor and Products Manager Professional for WooCommerceto a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
Who can be targeted by this issue?
An attacker must trick a logged-in privileged WordPress user into visiting a crafted page. The vulnerable update action lacks both CSRF nonce verification and user capability checks.
What changes can an attacker make?
Successful exploitation allows modification of arbitrary taxonomy terms.
Are installations running version 1.2.2 affected?
The issue affects BEAR versions before 1.2.2. Version 1.2.2 is not identified as affected by the provided information.