GHSA-mf8h-3jc5-v68jMediumCVSS 4.3

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field...

Published
September 12, 2026
Last Modified
September 12, 2026

🔗 CVE IDs covered (1)

📋 Description

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

🔗 References (3)