CVE-2026-18443: Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'accessprivileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal 'access-privilege' module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the administrator's role-based deny-list Access Privilege settings to explicitly block the internal 'access-privilege' module, preventing Subscriber-level users from invoking the vulnerable handler.
Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management role-based deny-list Access Privilege configuration = Explicitly block the internal 'access-privilege' module
Event History
Frequently Asked Questions
Which installations are exposed to Subscriber-level exploitation?
Exposure requires a saved role-based deny-list Access Privilege configuration in which the internal access-privilege module is not explicitly blocked. Under that condition, the authorization filter implicitly permits Subscriber-level users to reach the vulnerable handler.
What access does an attacker need?
An attacker needs an authenticated WordPress account with Subscriber-level access or higher. No user interaction is required.
What can successful exploitation allow?
An attacker can append SQL queries to existing queries through the access_privileges parameter and extract sensitive information from the database. The reported impact also includes privilege escalation.
How can administrators assess whether their configuration is affected?
Review saved role-based deny-list Access Privilege settings and determine whether the internal access-privilege module is explicitly blocked for Subscriber-level users. Installations without the described saved deny-list configuration do not meet the stated exploitation condition.