cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwoo-bulk-editor woo-bulk-editor

Direction: ascending
Jun 06, 2024

BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4942

CVE, Research URL

CVE-2023-4942

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4923

CVE, Research URL

CVE-2023-4923

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4920

CVE, Research URL

CVE-2023-4920

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Additionally, input sanitization and escaping is insufficient resulting in the possibility of malicious script injection.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-33314

CVE, Research URL

CVE-2023-33314

Date
May 28, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
Affected versions
max 1.1.3.2.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2024-31430

CVE, Research URL

CVE-2024-31430

Date
Apr 11, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through 1.0.8.1; BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.1.
Affected versions
max 1.1.4.2.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4924

CVE, Research URL

CVE-2023-4924

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4938

CVE, Research URL

CVE-2023-4938

Date
Oct 18, 2023
Research Description
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4941

CVE, Research URL

CVE-2023-4941

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2024-30463

CVE, Research URL

CVE-2024-30463

Date
Mar 29, 2024
Research Description
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.
Affected versions
max 1.1.4.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4935

CVE, Research URL

CVE-2023-4935

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4926

CVE, Research URL

CVE-2023-4926

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.1.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2024-24835

CVE, Research URL

CVE-2024-24835

Date
Mar 23, 2024
Research Description
Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
Affected versions
max 1.1.4.1.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2024-30200

CVE, Research URL

CVE-2024-30200

Date
Mar 28, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
Affected versions
max 1.1.4.3.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2024-24834

CVE, Research URL

CVE-2024-24834

Date
Feb 08, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: from n/a through 1.1.4.
Affected versions
max 1.1.4.1.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4937

CVE, Research URL

CVE-2023-4937

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4943

CVE, Research URL

CVE-2023-4943

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
Affected versions
max 1.1.4.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2023-4940

CVE, Research URL

CVE-2023-4940

Date
Oct 20, 2023
Research Description
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.1.4.
Status
vulnerable
Feb 18, 2025

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2025-26775

CVE, Research URL

CVE-2025-26775

Date
Feb 17, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR allows Stored XSS. This issue affects BEAR: from n/a through 1.1.4.4.
Affected versions
max 1.1.4.5.
Status
vulnerable
Apr 13, 2026

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2026-1673

CVE, Research URL

CVE-2026-1673

Date
Apr 08, 2026
Research Description
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for unauthenticated attackers to delete WooCommerce taxonomy terms (categories, tags, etc.) via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.
Affected versions
max 1.1.6.
Status
vulnerable

BEAR &#8211; Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net # CVE-2026-1672

CVE, Research URL

CVE-2026-1672

Date
Apr 08, 2026
Research Description
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_redraw_table_row() function. This makes it possible for unauthenticated attackers to update WooCommerce product data including prices, descriptions, and other product fields via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.
Affected versions
max 1.1.6.
Status
vulnerable