PT-2026-31290 · Automattic+1 · Woocommerce+1

Dmitry Ignatyev

·

Published

2026-04-08

·

Updated

2026-04-12

·

CVE-2026-1672

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net versions up to and including 1.1.5
Description The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is susceptible to Cross-Site Request Forgery due to missing nonce validation on the woobe redraw table row() function. This allows unauthenticated attackers to modify WooCommerce product data, including prices and descriptions, by tricking a site administrator or shop manager into performing an action.
Recommendations Versions up to and including 1.1.5 should be updated to a newer version that includes nonce validation for the woobe redraw table row() function.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-1672

Affected Products

Bear – Bulk Editor/Products Manager Professional For Woocommerce
Woocommerce