Executive brief
The BEAR WordPress plugin, used to manage WooCommerce product data in bulk, fails to verify security tokens before saving field configurations. An attacker can trick an administrator into visiting a malicious website and silently modify the plugin's settings, potentially injecting malicious field names or settings that could later be exploited or disrupt product management workflows.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) in the woobe_save_meta AJAX action that lacks nonce validation. An attacker crafts a hidden form on an external site that submits a GET request to the target WordPress admin-ajax.php endpoint with modified meta field configuration. When a logged-in administrator visits the attacker's page, the browser automatically includes valid WordPress authentication cookies (due to SameSite=Lax defaults), and the malicious configuration is saved. The plugin stores arbitrary meta keys and titles without verification, allowing an attacker to inject fields like "_csrf_injected" into the woobe_meta_fields option. The fix is available in version 1.2.2, which adds proper nonce validation.
Affected products
- WooCommerce BEAR - Bulk Editor and Products Manager Professional before 1.2.2
Timeline
- 2026-09-10: disclosed
- 2026-09-12: patched: Fixed in version 1.2.2