PT-2026-104542 · WordPress · Smart Manager – Advanced Woocommerce Bulk Edit & Inventory Management
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management versions prior to 8.97.1
Description
An issue exists where authenticated attackers with subscriber-level access and above can perform a generic SQL Injection. This occurs due to insufficient escaping of the user-supplied
access privileges parameter and a lack of sufficient preparation of the SQL query. The flaw allows attackers to append additional SQL queries to extract sensitive information from the database. This is possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal access-privilege module, allowing the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.Recommendations
Update the plugin to a version newer than 8.97.0.
Restrict access to the
access privileges parameter to minimize the risk of exploitation.Fix
LPE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Manager – Advanced Woocommerce Bulk Edit & Inventory Management