Impact
The Smart Manager WordPress plugin contains an SQL injection flaw where unsanitized input is incorporated into a database query, allowing a blind SQL injection. An attacker can extract or change information stored in the WordPress e‑commerce database, compromising the confidentiality and integrity of the site’s data. The description does not mention other functional impacts, such as denial of service or persistence, so the focus remains on data manipulation and exposure.
Affected Systems
Any WordPress installation running the smart‑manager‑for‑wp‑e‑commerce plugin version 8.52.0 or earlier by storeapps is affected. Sites that deploy these versions are vulnerable to this blind injection flaw.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while an EPSS score of less than 1 % suggests the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog. The description does not specify an authentication requirement, so the attack likely involves a remote HTTP request to a plugin‑controlled endpoint, where crafted input is injected into an unescaped SQL statement. Because the attack is blind, multiple requests are needed to infer database content, reducing the ease of exploitation but still enabling serious data compromise if successful.
OpenCVE Enrichment