CVE-2026-18443: Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter

Published Oct 3, 2026
·
Updated

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'accessprivileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal 'access-privilege' module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.

Affected Software

1 affected component
StoreApps Smart Manager<=8.97.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Configure the administrator's role-based deny-list Access Privilege settings to explicitly block the internal 'access-privilege' module, preventing Subscriber-level users from invoking the vulnerable handler.

    Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management role-based deny-list Access Privilege configuration = Explicitly block the internal 'access-privilege' module

Event History

Oct 3, 2026
CVE Published
via MITRE·06:38 AM
Data Sourced
via MITRE·06:38 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which installations are exposed to Subscriber-level exploitation?

Exposure requires a saved role-based deny-list Access Privilege configuration in which the internal access-privilege module is not explicitly blocked. Under that condition, the authorization filter implicitly permits Subscriber-level users to reach the vulnerable handler.

2

What access does an attacker need?

An attacker needs an authenticated WordPress account with Subscriber-level access or higher. No user interaction is required.

3

What can successful exploitation allow?

An attacker can append SQL queries to existing queries through the access_privileges parameter and extract sensitive information from the database. The reported impact also includes privilege escalation.

4

How can administrators assess whether their configuration is affected?

Review saved role-based deny-list Access Privilege settings and determine whether the internal access-privilege module is explicitly blocked for Subscriber-level users. Installations without the described saved deny-list configuration do not meet the stated exploitation condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203