Description
Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.
Published: 2026-07-13
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows users to perform bulk edit operations on products in WooCommerce without proper permission checks. Because the plugin does not enforce the correct access control, an attacker or an unauthorized user could modify product data, potentially altering pricing, availability, or other critical attributes. This flaw falls under CWE‑862, which describes failures to verify an entity’s rights to perform an action.

Affected Systems

The affected component is the WooCommerce Bulk Edit Products – WP Sheet Editor plugin, version 1.8.21 and earlier. The vendor is Jose Vega. Users who have installed this plugin in WordPress sites are affected.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, but the EPSS score of less than 1% shows exploitation is expected to be rare. The vulnerability is not listed in CISA KEV, suggesting it is not currently known as a widely exploited flaw. Based on the description, it is inferred that the likely attack vector is through a logged‑in user with an unexpected role that the plugin incorrectly trusts; exploiting the flaw would typically require access to the WordPress admin area with at least read permissions, but an attacker could co‑ordinate with a compromised account or elevate privileges through the plugin’s exposed bulk edit endpoints.

Generated by OpenCVE AI on July 31, 2026 at 11:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WooCommerce Bulk Edit Products – WP Sheet Editor to a version newer than 1.8.21.
  • Restrict the plugin’s functionality to administrators or trusted roles only, ensuring that only users who should edit products can do so.
  • Review the WordPress user roles and delete any unnecessary product editing permissions that might allow unintended access.

Generated by OpenCVE AI on July 31, 2026 at 11:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Jose Vega
Jose Vega woocommerce Bulk Edit Products – Wp Sheet Editor
Wordpress
Wordpress wordpress
Vendors & Products Jose Vega
Jose Vega woocommerce Bulk Edit Products – Wp Sheet Editor
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Jose Vega WooCommerce Bulk Edit Products – WP Sheet Editor woo-bulk-edit-products allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Bulk Edit Products – WP Sheet Editor: from n/a through <= 1.8.21.
Title WordPress WooCommerce Bulk Edit Products – WP Sheet Editor plugin <= 1.8.21 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Jose Vega Woocommerce Bulk Edit Products – Wp Sheet Editor
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:38:06.766Z

Reserved: 2026-07-13T06:13:34.179Z

Link: CVE-2026-61952

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:24.828Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses