Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
Published: 2025-01-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Smart Manager WordPress plugin contains an SQL injection flaw where unsanitized input is incorporated into a database query, allowing a blind SQL injection. An attacker can extract or change information stored in the WordPress e‑commerce database, compromising the confidentiality and integrity of the site’s data. The description does not mention other functional impacts, such as denial of service or persistence, so the focus remains on data manipulation and exposure.

Affected Systems

Any WordPress installation running the smart‑manager‑for‑wp‑e‑commerce plugin version 8.52.0 or earlier by storeapps is affected. Sites that deploy these versions are vulnerable to this blind injection flaw.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, while an EPSS score of less than 1 % suggests the likelihood of exploitation in the wild is low. The vulnerability is not listed in the CISA KEV catalog. The description does not specify an authentication requirement, so the attack likely involves a remote HTTP request to a plugin‑controlled endpoint, where crafted input is injected into an unescaped SQL statement. Because the attack is blind, multiple requests are needed to infer database content, reducing the ease of exploitation but still enabling serious data compromise if successful.

Generated by OpenCVE AI on June 18, 2026 at 03:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Smart Manager to a version newer than 8.52.0
  • Remove or deactivate the plugin if it is no longer required
  • Restrict access to the Smart Manager administrative pages to authenticated administrators only and block or filter unauthenticated requests to the plugin’s endpoints

Generated by OpenCVE AI on June 18, 2026 at 03:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StoreApps Smart Manager allows Blind SQL Injection. This issue affects Smart Manager: from n/a through 8.52.0. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Thu, 06 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StoreApps Smart Manager allows Blind SQL Injection. This issue affects Smart Manager: from n/a through 8.52.0.
Title WordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:05.782Z

Reserved: 2025-01-07T21:03:35.333Z

Link: CVE-2025-22710

cve-icon Vulnrichment

Updated: 2025-01-21T14:18:08.302Z

cve-icon NVD

Status : Deferred

Published: 2025-01-21T14:15:11.000

Modified: 2026-06-17T08:49:27.480

Link: CVE-2025-22710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T03:15:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')