CVE-2026-84025 PUBLISHED

BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download URL and Meta Disclosure via IDOR

Assigner: WPScan
Reserved: 01.09.2026 Published: 12.09.2026 Updated: 12.09.2026

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.

Product Status

Vendor Unknown
Product BEAR
Versions Default: unaffected
  • affected from 0 to 1.2.2 (excl.)

Credits

  • Ali Mousavi finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE