The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing nonce validation on the woobe_redraw_table_row() function. This makes it possible for unauthenticated attackers to update WooCommerce product data including prices, descriptions, and other product fields via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
This is N-day patch we releasing by testing our model capabilities
[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723
Fastjson RCE
[POC] CVE-2026-16723 — CVE-2026-16723
CVE-2026-16723 - Draft
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free