CVE-2026-84023
Received Received - Intake

CSRF to Term Modification in BEAR WordPress Plugin

Vulnerability report for CVE-2026-84023, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bear bulk_editor_and_products_manager_professional_for_woocommerce to 1.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Request Forgery (CSRF) vulnerability in the BEAR WordPress plugin before version 1.2.2. It allows an attacker to modify taxonomy terms without proper verification. The plugin fails to check for a CSRF nonce or user capabilities before updating terms, enabling unauthorized changes by tricking a logged-in privileged user into visiting a malicious page.

Detection Guidance

To detect this vulnerability, check the installed version of the BEAR plugin. If it is below 1.2.2, the system is vulnerable. You can verify the version via WordPress admin panel under Plugins or by inspecting the plugin files for version details.

Impact Analysis

An attacker could exploit this to modify taxonomy terms on your WordPress site without your permission. This could lead to unauthorized changes in product categories, tags, or other term-based data, potentially disrupting site functionality or spreading malicious content through your store.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized modifications to taxonomy terms, which may include sensitive data classifications or metadata. Unauthorized changes could lead to improper data handling or exposure, violating integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Immediately update the BEAR plugin to version 1.2.2 or later. If updating is not possible, consider disabling the plugin until an update is applied. Ensure all users with privileged access are aware of the risk and avoid visiting untrusted links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84023. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart