CyberRota Analysis
AI-GeneratedThe BEAR WordPress plugin prior to version 1.2.2 is vulnerable due to inadequate CSRF nonce verification and user capability checks, enabling attackers to manipulate taxonomy terms by enticing a logged-in privileged user to visit a malicious page. This flaw poses a risk of unauthorized changes to site content, which could lead to broader security issues or site integrity compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.