Extension WordPress
Vulnérabilités BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
Cette page rassemble les failles publiées pour BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net
24 fiches
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.8 – Unauthenticated Stored Cross-Site Scripting
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This…
*-1.1.8
1.1.9
29/06/2026
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 – Cross-Site Request Forgery
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation…
*-1.1.5
1.1.6
07/05/2026
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 – Cross-Site Request Forgery to Product Data Modification
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on…
*-1.1.5
1.1.6
07/04/2026
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 – Cross-Site Request Forgery to Taxonomy Term Deletion
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on…
*-1.1.5
1.1.6
07/04/2026
BEAR <= 1.1.7.1 – Authenticated (Shop manager+) SQL Injection
The BEAR plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-1.1.7.1
1.1.8
30/03/2026
BEAR <= 1.1.4.4 – Authenticated (Administrator+) Stored Cross-Site Scripting
The BEAR plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
*-1.1.4.4
1.1.4.5
14/02/2025
BEAR <= 1.1.4.1 & WOLF <= 1.0.8.1 – Cross-Site Request Forgery to Notice Dismissal
Multiple plugins and/or themes for WordPress are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on the admin_init() hook. This makes it possible for unauthenticated attackers to dismiss notices…
*-1.1.4.1
1.1.4.2
10/04/2024
BEAR <= 1.1.4.3 – Missing Authorization
The BEAR plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the woobe_update_page_field() function in versions up to, and including, 1.1.4.3. This makes it possible for unauthenticated attackers to update…
*-1.1.4.3
1.1.4.4
28/03/2024
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.4.2 – Reflected Cross-Site Scripting
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.1.4.2 due to insufficient input sanitization and output escaping.…
*-1.1.4.2
1.1.4.3
26/03/2024
BEAR <= 1.1.4 – Authenticated (Shop manager+) Stored Cross-Site Scripting via Plugin Options
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin options in all versions up to, and including, 1.1.4 due to insufficient input sanitization…
*-1.1.4
1.1.4.1
02/02/2024
BEAR <= 1.1.4 – Missing Authorization via Several Functions
The BEAR plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in the /ext/history/history.php file in versions up to, and including, 1.1.4. This makes it possible for authenticated attackers, with subscriber-level…
*-1.1.4
1.1.4.1
02/02/2024
BEAR <= 1.1.3.3 – Missing Authorization to Product Manipulation
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_apply_default_combination function. This makes it possible for authenticated attackers (subscriber or higher)…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Profile Deletion
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the delete_profile function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Missing Authorization to Product Manipulation
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to a missing capability check on the woobe_bulkoperations_swap function. This makes it possible for authenticated attackers (subscriber or higher)…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Product Deletion
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulk_delete_products function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Missing Authorization to Product Deletion
The BEAR for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.1.3.3. This is due to missing capability checks on the woobe_bulkoperations_delete function. This makes it possible for authenticated attackers, with subscriber access or…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Product Deletion
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_delete function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Profile Creation
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the create_profile function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_save_options function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
BEAR <= 1.1.3.3 – Cross-Site Request Forgery to Product Manipulation
The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is due to missing or incorrect nonce validation on the woobe_bulkoperations_apply_default_combination function. This makes it possible for unauthenticated attackers to…
*-1.1.3.3
1.1.4
25/09/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.