Impact
The vulnerability permits an unauthenticated attacker to inject arbitrary scripts into pages served by the Smart Manager plugin. This could affect the confidentiality and integrity of site visitors and is classified as CWE‑79 with a CVSS score of 7.1.
Affected Systems
The Smart Manager plugin for WordPress supplied by StoreApps, versions 8.90.0 and earlier, is vulnerable. Any WordPress installation deploying one of these versions is at risk.
Risk and Exploitability
The exploit requires no special permissions and can be executed remotely by submitting crafted input to the plugin’s interfaces. Based on the description, it is inferred that the likely attack vector is remote web input via crafted form submissions, as the formal data does not explicitly state the direct mode of attack. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Given this inferred attack vector, exposure is limited to traffic that transmits input to the plugin’s vulnerable endpoints.
OpenCVE Enrichment