CVE-2026-84024: Unknown Bear

Medium severity, CVSS 4.3. EPSS: 0.1% chance of exploitation in the next 30 days.

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.

Affected products

  • Unknown Bear: before 1.2.2 (fixed in 1.2.2)

Published 2026-09-12. Last modified 2026-09-14.