Cross-Site Request Forgery Vulnerability in Bulk Editor and Products Manager for WooCommerce by Pluginus.Net
CVE-2026-1672
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-1672?
The Bulk Editor and Products Manager Professional plugin for WooCommerce by Pluginus.Net is susceptible to a Cross-Site Request Forgery due to the absence of nonce validation in the woobe_redraw_table_row() function. This vulnerability allows unauthenticated attackers to exploit the plugin, facilitating unauthorized updates to WooCommerce product information, including prices and descriptions, by manipulating a site administrator or shop manager into executing a malicious request.
Affected Version(s)
BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net 0 <= 1.1.5