Sceawere
Vulnerability Detail
CVE-2026-18443UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Smart Manager
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- storeapps
- Product
- Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal 'access-privilege' module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-03T07:16:47.917Z",
"pubdate": "2026-10-03T07:16:47.917Z",
"executiveSummary": "The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress contains a critical SQL Injection vulnerability affecting all versions up to and including 8.97.0.\nThis vulnerability is rooted in the insufficient sanitization of the 'access_privileges' parameter, which fails to adequately escape user-supplied input before it is incorporated into database queries.\nAuthenticated attackers, including those with subscriber-level permissions, can exploit this flaw to inject arbitrary SQL commands. This capability enables the unauthorized extraction of sensitive information stored within the WordPress database.\nThe exploit requires a specific configuration state where an administrator has defined a role-based deny-list that inadvertently fails to restrict access to the 'access-privilege' module, thereby allowing the authorization filter to pass the request to the vulnerable handler.\nGiven the ability to exfiltrate data, this vulnerability poses a significant security risk to confidentiality, requiring immediate remediation to prevent unauthorized data access.",
"technicalDetails": "The vulnerability resides within the plugin's 'access_privileges' handler, which processes user-provided input. The root cause is identified as a failure to employ parameterization or rigorous escaping techniques when constructing SQL queries that incorporate user-controllable data.\nThe attack vector involves manipulating the 'access_privileges' parameter. Because the plugin does not properly validate or prepare this input, the database engine executes the attacker's injected SQL syntax alongside the intended query logic.\nThe exploitation flow is contingent upon the authorization layer's configuration. In environments where an administrator has configured a custom access privilege deny-list, the plugin's authorization filter evaluates permissions. If the 'access-privilege' module is not explicitly prohibited for low-privileged roles such as 'Subscriber', the system implicitly authorizes the user to interact with the vulnerable handler.\nOnce the authorization filter is bypassed, the attacker submits a specially crafted request containing malicious SQL fragments. These fragments escape the context of the original query, allowing for UNION-based or blind SQL injection techniques to be leveraged.\nPost-exploitation, the attacker can systematically probe the database structure to extract sensitive information, such as user credentials, personally identifiable information (PII), or WooCommerce store data. Because the injection occurs at the SQL layer, the attacker may also attempt to modify, delete, or add records, depending on the database user's privileges and the structure of the target query.\nThe vulnerability is active across all versions up to 8.97.0. It is network-exposed, as it is accessible through standard HTTP requests targeting the WordPress installation, provided the attacker maintains valid credentials with at least subscriber-level access."
}