SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-84023

MEDIUM · CVSS 6.5 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The BEAR WordPress plugin prior to version 1.2.2 is vulnerable due to inadequate CSRF nonce verification and user capability checks, enabling attackers to manipulate taxonomy terms by enticing a logged-in privileged user to visit a malicious page. This flaw poses a risk of unauthorized changes to site content, which could lead to broader security issues or site integrity compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-84023
Severity
MEDIUM
CVSS
6.5
EPSS
0.11%
WordPress

Original NVD Description

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.