BEAR <= 1.1.3.3 - Missing Authorization to Product Deletion
2023-09-25 00:00
Marco WotschkaStrategic Overview
StatusPatched in 1.1.4
Affected Version
<= 1.1.3.3CVSS5.4Medium
CVE
CVE-2023-4924Vulnerability Overview
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
Technical Analysis
REMEDIATION: Update to version 1.1.4, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C