Cross-Site Request Forgery Vulnerability in Pluginus.Net WooCommerce Product Manager
CVE-2026-1673
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-1673?
The BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net contains a vulnerability due to inadequate nonce validation in the woobe_delete_tax_term() function. As a result, unauthenticated attackers can exploit this flaw to delete taxonomies, including categories and tags, by tricking authenticated users, such as site administrators or shop managers, into executing a malicious action. It is crucial for users of this plugin to address this issue immediately to maintain the security of their WooCommerce stores.
Affected Version(s)
BEAR β Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net 0 <= 1.1.5