← WordPress Vulnerabilities
WordPress security by component

bear

bear is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 6.5.

Plugin slug: bear

CVE-2026-84025: BEAR exposes other owners' protected product data

BEAR before 1.2.2 accepts caller-supplied product identifiers in several data-returning handlers without checking ownership. A user restricted to their own products can read other owners' product information, including protected downloadable file URLs and private metadata. The authoritative export does not identify the handlers, identifier parameters, or full returned schema.

PublishedSep 12, 2026
Known safe version1.2.2
Published vulnerabilities for bear
Safe version
Sep 12, 2026 CVE-2026-84025
BEAR exposes other owners' protected product data
BEAR before 1.2.2 accepts caller-supplied product identifiers in several data-returning handlers without checking ownership. A user restricted to their own products can read other owners' product information, including protected downloadable file URLs and private metadata. The authoritative export does not identify the handlers, identifier parameters, or full returned schema.
1.2.2
CVE2.2
NVDPending
Sep 12, 2026 CVE-2026-84024
BEAR: Cross-site request forgery
BEAR is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is < 1.2.2.
1.2.2
CVE4.3
NVDPending
Sep 12, 2026 CVE-2026-84023
BEAR taxonomy update CSRF can modify arbitrary terms
BEAR before 1.2.2 updates taxonomy terms without verifying a CSRF nonce or checking the acting user's capabilities. An attacker can trick a logged-in privileged user into visiting a crafted page that modifies arbitrary terms. The authoritative export does not identify the handler, taxonomy, term identifier, or mutable fields.
1.2.2
CVE6.5
NVDPending