CVE-2026-84025: BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR
The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress BEAR - Bulk Editor and Products Manager Professional for WooCommerceto a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
Which users can access data they do not own?
Authenticated users who are restricted to managing only their own products may be able to retrieve information for products owned by other users.
What information could be exposed?
The affected handlers can disclose other owners' product information, including protected downloadable file URLs and private product metadata.
What product versions are affected?
Versions before 1.2.2 are affected.