Impact
The BEAR Bulk Editor and Products Manager Professional plugin for WooCommerce fails to validate a CSRF nonce when saving meta field configuration before version 1.2.2. An attacker who can entice a logged‑in administrator to a crafted URL can overwrite the plugin's settings without providing any additional authentication, resulting in an unauthorized change to product metadata that can alter product listings or ordering logic.
Affected Systems
WordPress sites that use the BEAR Bulk Editor and Products Manager Professional plugin less than version 1.2.2, which commonly appears on WooCommerce storefronts, are affected. The plugin's meta it. The specific affected versions are not enumerated beyond the <1.2.2 constraint, so any installation of the plugin below that release is potentially impacted. It is inferred that any installation earlier than 1.2.2 is vulnerable, as the description specifies lack of CSRF nonce before that release.
Risk and Exploitability
The CVSS score of 4.3 denotes moderate severity, while the EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is social engineering: the attacker must lure a logged‑in administrator to a crafted page that submits the configuration change, bypassing CSRF checks and allowing unauthorized credentials.
OpenCVE Enrichment