Impact
The Smart Manager plugin for WordPress exposes a SQL Injection flaw in the access_privileges parameter. Based on the description, it is inferred that an authenticated user with Subscriber or higher role can inject arbitrary SQL code. The vulnerability arises from insufficient escaping and lack of prepared statements, allowing the attacker to append and execute additional queries. Successful exploitation can extract sensitive data such as passwords, emails, or order details, and can be leveraged to elevate privileges within the WordPress site.
Affected Systems
All installations of storeapps Smart Manager – WooCommerce Bulk Edit, Products, Orders, Users & More (Spreadsheet) with versions up to and including 8.97.0 are affected. The flaw is present in every release through 8.97.0 regardless of WordPress version.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating severe impact. Although the EPSS score is not available, the lack of a KEV listing suggests no widespread exploitation has been reported, but the exploitation window remains open for attackers who can authenticate as a Subscriber or higher. Based on the description, it is inferred that the required conditions include a permissive deny-list Access Privilege configuration that does not explicitly block the internal access-privilege module, so a misconfiguration can transform a seemingly low-level role into a vector for elevated access. Attackers would need to craft an input containing the malicious SQL payload and submit it through a request to the vulnerable handler, resulting in data leakage and potential privilege escalation.
OpenCVE Enrichment