SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84025

LOW · CVSS 2.2 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The BEAR WordPress plugin prior to version 1.2.2 is vulnerable due to a lack of ownership checks, enabling unauthorized users to access product data associated with other owners, including sensitive downloadable file URLs and private metadata. This vulnerability poses a significant risk to site integrity and data privacy, making it essential for WordPress site administrators using this plugin to prioritize an update to version 1.2.2 or later to mitigate potential data leaks.

CVE
CVE-2026-84025
Severity
LOW
CVSS
2.2
EPSS
0.15%
WordPress

Original NVD Description

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.