CVE-2026-84024

CVE-2026-84024: BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Update via CSRF

Vendor Unknown
Product BEAR
Published September 12, 2026
Last update September 12, 2026

CVSS base score

What the vulnerability does

01Description

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

Key dates

02Disclosure timeline

September 12, 2026 CVE published
September 12, 2026 Record updated