CVE-2026-84024
Received Received - Intake

CSRF to Configuration Change in BEAR WordPress Plugin

Vulnerability report for CVE-2026-84024, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bear bulk_editor_and_products_manager_professional_for_woocommerce to 1.2.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The BEAR WordPress plugin before version 1.2.2 has a Cross-Site Request Forgery (CSRF) vulnerability. It fails to verify a CSRF nonce before saving its meta field configuration. This allows an attacker to trick a logged-in administrator into visiting a malicious page, which then overwrites the plugin's configuration.

Detection Guidance

Check the installed version of the BEAR plugin. If it is below 1.2.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress or inspect the plugin files directly.

Impact Analysis

An attacker could exploit this to change the plugin's settings without authorization. This might disrupt WooCommerce operations, alter product data, or expose sensitive information if the configuration changes affect security or data handling.

Compliance Impact

This vulnerability could lead to unauthorized changes in product or user data, potentially violating GDPR (data protection) or HIPAA (health data privacy) if sensitive information is altered or exposed. Compliance may be impacted if the plugin manages personal or health-related data.

Mitigation Strategies

Update the BEAR plugin to version 1.2.2 or later immediately. Remove or disable the plugin if an update is not possible. Ensure all administrators are aware of phishing risks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84024. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart