The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 08:36
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://plugins.trac.wordpress.org/browser/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php#L521 - Third Party Advisory | |
| References | () https://plugins.trac.wordpress.org/changeset/2970262/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php?contextall=1&old=2844667&old_path=%2Fwoo-bulk-editor%2Ftrunk%2Fext%2Fbulkoperations%2Fbulkoperations.php - Third Party Advisory | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/31c5e524-ef4d-48c7-baa0-595f8060a167?source=cve - Third Party Advisory | 
25 Oct 2023, 10:01
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | 
        
        Pluginus bear - Woocommerce Bulk Editor And Products Manager Professional
         Pluginus  | 
|
| CWE | CWE-352 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 4.3  | 
| References | (MISC) https://plugins.trac.wordpress.org/browser/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php#L521 - Third Party Advisory | |
| References | (MISC) https://plugins.trac.wordpress.org/changeset/2970262/woo-bulk-editor/trunk/ext/bulkoperations/bulkoperations.php?contextall=1&old=2844667&old_path=%2Fwoo-bulk-editor%2Ftrunk%2Fext%2Fbulkoperations%2Fbulkoperations.php - Third Party Advisory | |
| References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/31c5e524-ef4d-48c7-baa0-595f8060a167?source=cve - Third Party Advisory | |
| CPE | cpe:2.3:a:pluginus:bear_-_woocommerce_bulk_editor_and_products_manager_professional:*:*:*:*:*:wordpress:*:* | 
20 Oct 2023, 07:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-10-20 07:15
Updated : 2024-11-21 08:36
NVD link : CVE-2023-4940
Mitre link : CVE-2023-4940
CVE.ORG link : CVE-2023-4940
JSON object : View
Products Affected
                pluginus
- bear_-_woocommerce_bulk_editor_and_products_manager_professional
 
CWE
                
                    
                        
                        CWE-352
                        
            Cross-Site Request Forgery (CSRF)
