Pluginus.Net BEAR - Bulk Editor and Products Manager Professional
cpe:2.3:a:pluginus:bear_-_woocommerce_bulk_editor_and_products_manager_professional:*:*:*:*:wordpress:*:*
- <= 1.1.5
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the BEAR - Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net. This vulnerability affects all versions through 1.1.5 and stems from inadequate nonce validation in the woobe_redraw_table_row() function. As a result, unauthenticated attackers can manipulate WooCommerce product data, including prices and descriptions, by tricking an administrator or shop manager into clicking a link that sends a forged request.
Exploitation of this vulnerability allows for unauthorized modification of WooCommerce product data, including prices and descriptions.
To reproduce this vulnerability, an attacker must trick a site administrator or shop manager into clicking a link that initiates a request to the woobe_redraw_table_row() function without the required nonce. This can be done by creating a forged request that appears to come from a trusted source.
Users are advised to update the plugin to version 1.1.6 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.