Junglewise Threat Intelligence

CVE-2026-1672: Pluginus.Net BEAR Bulk Editor CSRF in woobe_redraw_table_row

CVE-2026-1672 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: PluginUs.Net BEAR – Bulk Editor and Products Manager Professional for WooCommerce. Vendors: RealMag777, PluginUs.Net.

Executive brief

The BEAR Bulk Editor plugin for WordPress, which is used to manage WooCommerce product catalogs, contains a security flaw that allows unauthorized changes to store data. By tricking a site administrator or shop manager into clicking a malicious link, an attacker can remotely modify product details such as prices and descriptions. This could lead to financial loss through unauthorized discounts or damage to a store's reputation through altered product information.

Technical details

The BEAR Bulk Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce validation on the 'woobe_redraw_table_row' AJAX function. This function processes product updates by accepting a 'product_id', 'field', and 'value' without verifying the request's origin. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator or shop manager into executing it via social engineering (e.g., clicking a link). Successful exploitation allows the attacker to update WooCommerce product fields, including sale prices and descriptions, inheriting the victim's administrative permissions. The issue is fixed in version 1.1.6.

Affected products

  • realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5

Timeline

  • 2026-01-15: other: Vulnerability discovered and reported to vendor
  • 2026-04-07: disclosed: Public disclosure of vulnerability
  • 2026-04-08: advisory: NVD publication date

References

Related threats