The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.
CVE-2026-84024
NONE
EPSS 0.10%
Updated Sep 12, 2026
Meta
CVE Details
CVE ID
CVE-2026-84024
Published Date
Sep 12, 2026
Vendor
Meta
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.10%
Likelihood of exploitation in next 30 days
Percentile:
0.8th percentile (higher than 0.8% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory