← WordPress Vulnerabilities
WordPress security by component

BEAR

BEAR is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jun 29, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: woo-bulk-editor

CVE-2026-57320: BEAR: Cross-site scripting

BEAR is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.1.8.

PublishedJun 29, 2026
Known safe version1.1.9
Safe version
Jun 29, 2026 CVE-2026-57320
BEAR: Cross-site scripting
BEAR is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.1.8.
1.1.9
CVE7.1
NVDPending
May 12, 2026 CVE-2026-45213
BEAR: SQL injection
BEAR is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.1.7.1.
1.1.8
CVE7.6
NVDPending
May 07, 2026 CVE-2026-27415
BEAR: Cross-site request forgery
BEAR is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.1.5.
1.1.6
CVE4.3
NVDPending
Apr 08, 2026 CVE-2026-1673
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: Cross-site request forgery
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.1.5.
> 1.1.5
CVE4.3
NVDPending
Apr 08, 2026 CVE-2026-1672
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: Cross-site request forgery
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.1.5.
> 1.1.5
CVE6.5
NVDPending
Mar 29, 2024 CVE-2024-30463
BEAR: A security weakness
BEAR is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD5.3
Mar 28, 2024 CVE-2024-30200
BEAR: Cross-site scripting
BEAR is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Mar 23, 2024 CVE-2024-24835
BEAR: A security weakness
BEAR is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD6.5
Feb 08, 2024 CVE-2024-24834
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net: Cross-site scripting
BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Oct 20, 2023 CVE-2023-4941
Woo Bulk Editor: A security weakness
Woo Bulk Editor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4926
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Oct 20, 2023 CVE-2023-4924
Woo Bulk Editor: A security weakness
Woo Bulk Editor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD4.3
Oct 20, 2023 CVE-2023-4923
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Oct 20, 2023 CVE-2023-4943
Woo Bulk Editor: A security weakness
Woo Bulk Editor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4942
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4940
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4937
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4935
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Oct 20, 2023 CVE-2023-4920
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Oct 18, 2023 CVE-2023-4938
Woo Bulk Editor: A security weakness
Woo Bulk Editor is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
May 28, 2023 CVE-2023-33314
Woo Bulk Editor: Cross-site request forgery
Woo Bulk Editor is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD8.8