PT-2026-104542 · WordPress · Smart Manager – Advanced Woocommerce Bulk Edit & Inventory Management

·

CVE-2026-18443

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management versions prior to 8.97.1
Description An issue exists where authenticated attackers with subscriber-level access and above can perform a generic SQL Injection. This occurs due to insufficient escaping of the user-supplied access privileges parameter and a lack of sufficient preparation of the SQL query. The flaw allows attackers to append additional SQL queries to extract sensitive information from the database. This is possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal access-privilege module, allowing the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.
Recommendations Update the plugin to a version newer than 8.97.0. Restrict access to the access privileges parameter to minimize the risk of exploitation.

Fix

LPE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18443

Affected Products

Smart Manager – Advanced Woocommerce Bulk Edit & Inventory Management