Junglewise Threat Intelligence

CVE-2026-45213: RealMag777 BEAR woo-bulk-editor SQL injection

CVE-2026-45213 · Severity: high · CVSS 7.6 · Published 2026-05-12

Vendors: RealMag777.

Executive brief

The BEAR Bulk Editor plugin for WooCommerce, which helps store owners manage large inventories, contains a security flaw that could allow an attacker to access sensitive database information. An attacker with high-level administrative or shop manager privileges could use this vulnerability to extract data they are not authorized to see. While the risk is mitigated by the requirement for high-level access, it could lead to the exposure of customer or business data.

Technical details

A Blind SQL Injection vulnerability exists in the RealMag777 BEAR (woo-bulk-editor) plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw affects versions up to and including 1.1.7.1. An attacker with 'Shop Manager' or higher privileges can exploit this over the network without user interaction to perform unauthorized database queries. This can lead to the exfiltration of sensitive data from the WordPress database. The issue has been addressed in version 1.1.8.

Affected products

  • RealMag777 BEAR - Bulk Editor and Products Manager for WooCommerce <= 1.1.7.1

Timeline

  • 2026-02-28: other: Vulnerability reported by researcher daroo
  • 2026-03-30: patched: Patch released in version 1.1.8
  • 2026-05-12: disclosed: CVE published to NVD

References