Executive brief
The BEAR Bulk Editor plugin for WordPress, which is used to manage WooCommerce product catalogs, contains a security flaw that allows unauthorized changes to store data. By tricking a site administrator or shop manager into clicking a malicious link, an attacker can remotely modify product details such as prices and descriptions. This could lead to financial loss through unauthorized discounts or damage to a store's reputation through altered product information.
Technical details
The BEAR Bulk Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce validation on the 'woobe_redraw_table_row' AJAX function. This function processes product updates by accepting a 'product_id', 'field', and 'value' without verifying the request's origin. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a logged-in administrator or shop manager into executing it via social engineering (e.g., clicking a link). Successful exploitation allows the attacker to update WooCommerce product fields, including sale prices and descriptions, inheriting the victim's administrative permissions. The issue is fixed in version 1.1.6.
Affected products
- realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5
Timeline
- 2026-01-15: other: Vulnerability discovered and reported to vendor
- 2026-04-07: disclosed: Public disclosure of vulnerability
- 2026-04-08: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/woo-bulk-editor/trunk/index.php
- https://plugins.trac.wordpress.org/changeset/3457263/
- https://plugins.trac.wordpress.org/changeset/3465138/
- https://research.cleantalk.org/cve-2026-1672/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bc3b5faa-1a29-4fa7-9146-d782adce0b1f?source=cve