Executive brief
The BEAR Bulk Editor plugin for WooCommerce is used by site owners to manage large product catalogs. A security flaw allows an attacker to trick a site administrator into clicking a link that silently deletes store categories, tags, or other organizational terms. This can disrupt the online store's navigation and product organization, potentially impacting sales and customer experience.
Technical details
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce validation on the 'woobe_delete_tax_term' AJAX function. An unauthenticated attacker can exploit this by tricking a logged-in administrator or shop manager into visiting a malicious website or clicking a crafted link. The forged request triggers the vulnerable function, which accepts 'tax_key' and 'term_id' parameters without verifying the request's origin. This allows the attacker to delete product categories, tags, or other taxonomy terms, compromising the integrity of the WooCommerce store's catalog structure. The issue is fixed in version 1.1.6.
Affected products
- realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5
Timeline
- 2026-01-16: other: Vulnerability detected and reported to vendor
- 2026-04-07: disclosed: Public disclosure by Wordfence
- 2026-04-08: advisory: NVD published date
References
- https://plugins.trac.wordpress.org/browser/woo-bulk-editor/trunk/index.php
- https://plugins.trac.wordpress.org/changeset/3457263/
- https://plugins.trac.wordpress.org/changeset/3465138/
- https://research.cleantalk.org/cve-2026-1673/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1e4e8960-b0c1-4dbb-ba97-e45b88fb06c0?source=cve