Sceawere

Vulnerability Detail

CVE-2026-18443UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Smart Manager

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
storeapps
Product
Smart Manager – WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal 'access-privilege' module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-03T07:16:47.917Z",
  "pubdate": "2026-10-03T07:16:47.917Z",
  "executiveSummary": "The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress contains a critical SQL Injection vulnerability affecting all versions up to and including 8.97.0.\nThis vulnerability is rooted in the insufficient sanitization of the 'access_privileges' parameter, which fails to adequately escape user-supplied input before it is incorporated into database queries.\nAuthenticated attackers, including those with subscriber-level permissions, can exploit this flaw to inject arbitrary SQL commands. This capability enables the unauthorized extraction of sensitive information stored within the WordPress database.\nThe exploit requires a specific configuration state where an administrator has defined a role-based deny-list that inadvertently fails to restrict access to the 'access-privilege' module, thereby allowing the authorization filter to pass the request to the vulnerable handler.\nGiven the ability to exfiltrate data, this vulnerability poses a significant security risk to confidentiality, requiring immediate remediation to prevent unauthorized data access.",
  "technicalDetails": "The vulnerability resides within the plugin's 'access_privileges' handler, which processes user-provided input. The root cause is identified as a failure to employ parameterization or rigorous escaping techniques when constructing SQL queries that incorporate user-controllable data.\nThe attack vector involves manipulating the 'access_privileges' parameter. Because the plugin does not properly validate or prepare this input, the database engine executes the attacker's injected SQL syntax alongside the intended query logic.\nThe exploitation flow is contingent upon the authorization layer's configuration. In environments where an administrator has configured a custom access privilege deny-list, the plugin's authorization filter evaluates permissions. If the 'access-privilege' module is not explicitly prohibited for low-privileged roles such as 'Subscriber', the system implicitly authorizes the user to interact with the vulnerable handler.\nOnce the authorization filter is bypassed, the attacker submits a specially crafted request containing malicious SQL fragments. These fragments escape the context of the original query, allowing for UNION-based or blind SQL injection techniques to be leveraged.\nPost-exploitation, the attacker can systematically probe the database structure to extract sensitive information, such as user credentials, personally identifiable information (PII), or WooCommerce store data. Because the injection occurs at the SQL layer, the attacker may also attempt to modify, delete, or add records, depending on the database user's privileges and the structure of the target query.\nThe vulnerability is active across all versions up to 8.97.0. It is network-exposed, as it is accessible through standard HTTP requests targeting the WordPress installation, provided the attacker maintains valid credentials with at least subscriber-level access."
}
CVE-2026-18443: SQL Injection in Smart Manager (HIGH Severity, CVSS: 8.8) | Sceawere