Junglewise Threat Intelligence

CVE-2026-61952: Jose Vega WP Sheet Editor Missing Authorization in WooCommerce Bulk Edit

CVE-2026-61952 · Severity: medium · CVSS 4.9 · Published 2026-07-13

Executive brief

A security vulnerability exists in the WP Sheet Editor plugin for WooCommerce, which is used by site administrators to manage product listings in a spreadsheet-like interface. Due to incorrect access control settings, certain authorized users may be able to perform actions or modify product data beyond their intended permission levels. This could lead to unauthorized changes to store inventory or product details, though it requires the attacker to already have high-level access to the site.

Technical details

The vulnerability (CWE-862) stems from missing authorization checks within the 'woo-bulk-edit-products' plugin. An attacker with high-level privileges (PR:H) can exploit incorrectly configured access control security levels to perform unauthorized modifications to product data. The attack is reachable over the network without user interaction, but its impact is limited to integrity (I:H) without affecting confidentiality or availability. The issue is resolved in version 1.8.22.

Affected products

  • Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor n/a through 1.8.21

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory
  • 1.8.22: patched: First unaffected version reported by vendor.

References