THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-84025 (LOW 2.2) — The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadabl

[NVD] CVE-2026-84025 (LOW 2.2) — The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadabl

mednvdPublished 2026-09-12

CVE-2026-84025 CVSS: 2.2 LOW Published: 2026-09-12T06:16:26.700

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84025