Loading HuntDB...

GHSA-9f28-p89f-245f

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.

Related CVEs

Key Information

GHSA ID
GHSA-9f28-p89f-245f
Published
October 20, 2023 9:30 AM
Last Modified
April 4, 2024 8:50 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.