BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting
high
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 7.2
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.9
- Disclosed:
- Jun 29, 2026
CVE-2026-57320 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery
medium
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to p...
- CVSS:
- 4.3
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- May 7, 2026
CVE-2026-27415 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification
medium
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_redraw_table_row() function. This makes it possible for unauthentica...
- CVSS:
- 6.5
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Apr 7, 2026
CVE-2026-1672 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion
medium
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_delete_tax_term() function. This makes it possible for unauthenticat...
- CVSS:
- 4.3
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.6
- Disclosed:
- Apr 7, 2026
CVE-2026-1673 on NVD →
BEAR <= 1.1.7.1 - Authenticated (Shop manager+) SQL Injection
medium
The BEAR plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with shop manager-level access and above, t...
- CVSS:
- 4.9
- Affected:
- up to 1.1.7.1
- Fixed in:
- 1.1.8
- Disclosed:
- Mar 30, 2026
CVE-2026-45213 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.5
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 BEAR allows Stored XSS. This issue affects BEAR: from n/a through 1.1.4.4.
- Affected:
- up to 1.1.4.5
- Fixed in:
- 1.1.4.5
- Disclosed:
- Feb 17, 2025
CVE-2025-26775 on NVD →
BEAR <= 1.1.4.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The BEAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 5.5
- Affected:
- up to 1.1.4.4
- Fixed in:
- 1.1.4.5
- Disclosed:
- Feb 14, 2025
CVE-2025-26775 on NVD →
BEAR <= 1.1.4.1 & WOLF <= 1.0.8.1 - Cross-Site Request Forgery to Notice Dismissal
medium
Multiple plugins and/or themes for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on the admin_init() hook. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted they can trick a site adminis...
- CVSS:
- 5.3
- Affected:
- up to 1.1.4.1
- Fixed in:
- 1.1.4.2
- Disclosed:
- Apr 10, 2024
CVE-2024-31430 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net.This issue affects WOLF – WordPress Posts Bulk Editor and Manager Professional: from n/a through...
- Affected:
- up to 1.1.4.2
- Fixed in:
- 1.1.4.2
- Disclosed:
- Apr 10, 2024
CVE-2024-31430 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.4
unknown
[en] Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.3.
- Affected:
- up to 1.1.4.4
- Fixed in:
- 1.1.4.4
- Disclosed:
- Mar 29, 2024
CVE-2024-30463 on NVD →
BEAR <= 1.1.4.3 - Missing Authorization
medium
The BEAR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woobe_update_page_field() function in versions up to, and including, 1.1.4.3. This makes it possible for unauthenticated attackers to update page details.
- CVSS:
- 5.3
- Affected:
- up to 1.1.4.3
- Fixed in:
- 1.1.4.4
- Disclosed:
- Mar 28, 2024
CVE-2024-30463 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
- Affected:
- up to 1.1.4.3
- Fixed in:
- 1.1.4.3
- Disclosed:
- Mar 28, 2024
CVE-2024-30200 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.4.2 - Reflected Cross-Site Scripting
medium
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 1.1.4.2
- Fixed in:
- 1.1.4.3
- Disclosed:
- Mar 26, 2024
CVE-2024-30200 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.1
unknown
[en] Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
- Affected:
- up to 1.1.4.1
- Fixed in:
- 1.1.4.1
- Disclosed:
- Mar 23, 2024
CVE-2024-24835 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net allows Stored XSS.This issue affects BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus...
- Affected:
- up to 1.1.4.1
- Fixed in:
- 1.1.4.1
- Disclosed:
- Feb 8, 2024
CVE-2024-24834 on NVD →
BEAR <= 1.1.4 - Authenticated (Shop manager+) Stored Cross-Site Scripting via Plugin Options
medium
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin options in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 5.5
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4.1
- Disclosed:
- Feb 2, 2024
CVE-2024-24834 on NVD →
BEAR <= 1.1.4 - Missing Authorization via Several Functions
medium
The BEAR plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the /ext/history/history.php file in versions up to, and including, 1.1.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthori...
- CVSS:
- 5.3
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4.1
- Disclosed:
- Feb 2, 2024
CVE-2024-24835 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4937 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they ca...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4926 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4941 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request grante...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4942 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4943 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted th...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4920 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4940 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a si...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4935 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4924 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they c...
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 20, 2023
CVE-2023-4923 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4
unknown
[en] The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.4
- Disclosed:
- Oct 18, 2023
CVE-2023-4938 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can tri...
- CVSS:
- 5.4
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4926 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Deletion
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to delete products via a forged request granted they can tr...
- CVSS:
- 5.4
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4923 on NVD →
BEAR <= 1.1.3.3 - Missing Authorization to Product Deletion
medium
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or higher, to delete products.
- CVSS:
- 5.4
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4924 on NVD →
BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4941 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Profile Deletion
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the delete_profile function. This makes it possible for unauthenticated attackers to delete profiles via a forged request granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4935 on NVD →
BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4938 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Profile Creation
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to create profiles via a forged request granted they can trick a site ad...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4935 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4920 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to manipulate products via a forged requ...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4937 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_swap function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4940 on NVD →
BEAR <= 1.1.3.3 - Missing Authorization to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_visibility function. This makes it possible for authenticated attackers (subscriber or higher) to manipulate products.
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4943 on NVD →
BEAR <= 1.1.3.3 - Cross-Site Request Forgery to Product Manipulation
medium
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_visibility function. This makes it possible for unauthenticated attackers to manipulate products via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 1.1.3.3
- Fixed in:
- 1.1.4
- Disclosed:
- Sep 25, 2023
CVE-2023-4942 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.3.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR plugin <= 1.1.3.1 versions.
- Affected:
- up to 1.1.3.2
- Fixed in:
- 1.1.3.2
- Disclosed:
- May 28, 2023
CVE-2023-33314 on NVD →
BEAR <= 1.1.3.1 - Cross-Site Request Forgery via Multiple Functions
medium
The BEAR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.1. This is due to missing or incorrect nonce validation on the woobe_create_new_product, woobe_duplicate_products, and woobe_delete_products functions. This makes it possible for unauthenticated attackers t...
- CVSS:
- 6.5
- Affected:
- up to 1.1.3.1
- Fixed in:
- 1.1.3.2
- Disclosed:
- May 22, 2023
CVE-2023-33314 on NVD →
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net [woo-bulk-editor] < 1.1.4.1
unknown
Update the WordPress BEAR plugin to the latest available version (at least 1.1.4.1).
Mika discovered and reported this Broken Access Control vulnerability in WordPress BEAR Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an un...
- Affected:
- up to 1.1.4.1
- Fixed in:
- 1.1.4.1