Impact
StoreApps Smart Manager plugin versions up to 8.85.0 contain a bug in the privilege‑assignment logic that allows a user to gain higher privileges than originally granted. An attacker leveraging this flaw can elevate their role, potentially turning a non‑admin account into an administrator or granting access to restricted management functions. The core weakness is a misuse of capability checks, which is categorized as CWE‑266.
Affected Systems
The vulnerability impacts the StoreApps Smart Manager WordPress plugin, specifically all releases from the earliest version through 8.85.0. Any WordPress site installing this plugin within that range is at risk, regardless of the other plugins or themes in use.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated user who can access the plugin’s settings, or an attacker who can manipulate plugin configuration files or database entries. Successful exploitation would result in elevated privileges that compromise confidentiality, integrity, and availability of the WordPress site.
OpenCVE Enrichment