Ni WooCommerce Bulk Product Editor
Ni WooCommerce Bulk Product Editor has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Ni WooCommerce Bulk Product Editor has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by thiennv. Ni WooCommerce Bulk Product Editor is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2024-54236Ni WooCommerce Bulk Product Editor <= 1.4.5 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Ni WooCommerce Bulk Product Editor
Author
Anzar Ahmed
Ni WooCommerce Product Editor plugin lists all products in edit mode and lets you change the product name, SKU, price, quantity, and other product information easily. Ni WooCommerce Product Editor help you to manage the WooCommerce product price, product stock, product status, product Quantity, product SKU and many other product fields. Show all product type in separate tab, first tab show simple product, second tab variable product and third tab show variation product. Product information are display in tabular format and it’s easily updateable by clicking on update button. Additionally provide the option to filter the product on product name, provide the Ajax pagination and Ajax update for better user experience. Key feature Separate product lists for each product type: simple, variation, and variable. Easily update product stock. Search products by name. Manage product inventory. Ajax filter, search, and pagination for better user experience. Support/Feedback Email/New Report Requirement We welcome your suggestions and feedback. support@naziinfotech.com Disclaimer It is not responsible for any harm or wrong doing this Plugin may cause. Users are fully responsible for their own use. This Plugin is to be used WITHOUT warranty.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C