Skip to content
Threat Feed
high advisory

SQL Injection in Smart Manager for WooCommerce

An authenticated SQL injection vulnerability in the Smart Manager plugin for WordPress allows subscriber-level users to perform database exfiltration through the access_privileges parameter.

CVE search metadata

CVE search record: CVE-2026-18443. Severity: high. CVSS: 8.8. KEV: no. Product: Smart Manager for WooCommerce (<= 8.97.0). Brief: SQL Injection in Smart Manager for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-smart-manager-sql-injection/

The Smart Manager for WooCommerce plugin (versions 8.97.0 and below) contains a critical SQL injection vulnerability identified as CVE-2026-18443. The flaw exists due to inadequate input sanitization and lack of parameterized queries within the 'access_privileges' parameter handling logic. Attackers with at least subscriber-level access can manipulate database queries to exfiltrate sensitive information. This exploitation vector is specifically viable on installations where an administrator has configured a role-based deny-list for Access Privileges but failed to explicitly exclude the internal 'access-privilege' module. Because of this oversight, the authorization filter erroneously permits lower-privileged users to invoke the vulnerable handler, enabling unauthorized database interaction.

Impact

Successful exploitation allows authenticated attackers with subscriber-level access to execute arbitrary SQL commands against the underlying WordPress database. This can lead to the unauthorized extraction of sensitive business data, customer information, or administrative credentials stored within the WooCommerce environment. The vulnerability impacts all WordPress installations running the affected plugin versions where specific, non-restrictive access configurations are present.

Recommendation

  • Upgrade the 'Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management' plugin to the latest version (above 8.97.0) immediately.
  • Review role-based Access Privilege configurations in the Smart Manager dashboard to ensure the 'access-privilege' module is explicitly restricted for all non-administrative user roles.
  • Audit database access logs and monitor for anomalous SQL syntax errors or query patterns originating from subscriber-level user sessions.

Immediate actions

Upgrade Smart Manager for WooCommerce to a version higher than 8.97.0

IT Operations 48h

Mitigations

Review and restrict role-based Access Privileges in Smart Manager settings

immediate IT Operations

CVE-2026-18443

Detection coverage 1

Detects CVE-2026-18443 Exploitation - SQL Injection via access_privileges

high

Detects exploitation of CVE-2026-18443 by monitoring for SQL injection patterns in HTTP requests targeting the Smart Manager access_privileges handler

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →