BEAR Bulk Editor and Products Manager Professional for WooCommerce Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the BEAR - Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net. This vulnerability affects all versions through 1.1.5 and stems from inadequate nonce validation in the woobe_redraw_table_row() function. As a result, unauthenticated attackers can manipulate WooCommerce product data, including prices and descriptions, by tricking an administrator or shop manager into clicking a link that sends a forged request.

Impact

Exploitation of this vulnerability allows for unauthorized modification of WooCommerce product data, including prices and descriptions.

Reproduction

To reproduce this vulnerability, an attacker must trick a site administrator or shop manager into clicking a link that initiates a request to the woobe_redraw_table_row() function without the required nonce. This can be done by creating a forged request that appears to come from a trusted source.

Remediation

Users are advised to update the plugin to version 1.1.6 or later, where this vulnerability has been patched.

Added: Apr 8, 2026, 12:57 PM
Updated: Apr 8, 2026, 12:57 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
7.4
remediation
7.7
relevance
5.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.