๐Ÿ” CVE Alert

CVE-2026-84025

LOW 2.2

BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR

CVSS Score
2.2
EPSS Score
0.0%
EPSS Percentile
0th

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.

Vendor unknown
Product bear
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown bear

Be the first to know when new low vulnerabilities affecting unknown bear are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / BEAR
0 < 1.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/468a9f1a-1a16-410f-97a0-8a87a974df21/

Credits

Ali Mousavi WPScan