Description
Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0.
Published: 2026-02-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized modification of product data
Action: Apply Patch
AI Analysis

Impact

A missing authorization check in the WooCommerce Bulk Product Editor plugin allows an attacker with administrative interface access to perform privileged operations on product records. An attacker who can reach the plugin’s administrative pages may add, edit or delete products without proper permission verification, thereby compromising the integrity of store inventory. The flaw is a classic broken access control vulnerability (CWE‑862) that can directly alter product information, pricing, and availability, potentially leading to financial loss or erosion of customer trust.

Affected Systems

The issue affects the WooCommerce Bulk Product Editor plugin developed by vanquish and applies to all releases up to and including version 3.0. Users running any of these versions are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1 % shows that the probability of exploitation is currently very low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires access to the WordPress admin area, and the attacker must authenticate with a role that the plugin incorrectly trusts as having full product management rights. This means an attacker who can log in as an editor or developer, or who exploits a separate authentication weakness, can exploit the access‑control flaw. The risk is elevated for sites that expose the plugin’s administrative pages to untrusted users or that have weak role configurations.

Generated by OpenCVE AI on April 28, 2026 at 17:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WooCommerce Bulk Product Editor to any version newer than 3.0, when such a release is available.
  • If an upgrade cannot be performed immediately, enforce strict role‑based access control by restricting all Bulk Product Editor actions to administrators only, using WordPress role manager or a security plugin.
  • If the plugin is not required for immediate operations, disable or remove it from the site until a fixed release is available.

Generated by OpenCVE AI on April 28, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 25 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Vanquish
Vanquish woocommerce Bulk Product Editor
Wordpress
Wordpress wordpress
Vendors & Products Vanquish
Vanquish woocommerce Bulk Product Editor
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in vanquish WooCommerce Bulk Product Editor woocommerce-quick-product-editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Product Editor: from n/a through <= 3.0.
Title WordPress WooCommerce Bulk Product Editor plugin <= 3.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Vanquish Woocommerce Bulk Product Editor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:57:25.741Z

Reserved: 2025-12-31T20:13:05.452Z

Link: CVE-2025-69381

cve-icon Vulnrichment

Updated: 2026-02-25T15:00:19.544Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:22.707

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T17:45:16Z

Weaknesses