MEDIUM (5.0)
    Plugin

    Cross-Site Request Forgery in BEAR Bulk Editor and Products Manager for WooCommerce

    Published Date: 4/8/2026
    CVE ID: CVE-2026-1672

    Summary

    The BEAR – Bulk Editor and Products Manager Professional by Pluginus.Net plugin for WooCommerce contains a Cross-Site Request Forgery (CSRF) vulnerability that affects all versions up to 1.1.5. This flaw allows attackers to potentially manipulate WooCommerce product data by tricking site administrators into executing unintended actions.

    Vulnerability Details

    The vulnerability in question arises from the lack of nonce validation in the woobe_redraw_table_row() function within the BEAR Bulk Editor and Products Manager plugin. Nonce validation is a critical security mechanism designed to ensure that requests are genuine and initiated by authorized users, preventing CSRF attacks. Without this safeguard, attackers can craft malicious requests that, if visited by an authenticated user such as an administrator or shop manager, could result in unintended product data changes. Exploiting this vulnerability, attackers could manipulate product prices, descriptions, and other settings, which can be detrimental to the store’s integrity and financial operations. Such an attack typically requires social engineering tactics, where an attacker must deceive a user into clicking on a malicious link. The absence of nonce validation hence presents a serious risk that compromise sensitive business data.

    Recommendations

    To mitigate this vulnerability, it is crucial to implement nonce validation for the woobe_redraw_table_row() function. Educating administrators and users to be cautious about clicking on suspicious links can also help reduce risks. In addition, utilizing web application firewalls (WAF) and monitoring traffic for unusual patterns may provide an additional layer of protection against CSRF attacks.

    Available Fixes

    Last Updated: 4/13/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More