PT-2026-31290 · Realmag777 · Bear – Bulk Editor/Products Manager Professional For Woocommerce By Pluginus.Net

Dmitry Ignatyev

·

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-1672

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe redraw table row() function. This makes it possible for unauthenticated attackers to update WooCommerce product data including prices, descriptions, and other product fields via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-1672

Affected Products

Bear – Bulk Editor/Products Manager Professional For Woocommerce By Pluginus.Net