SQL Injection in Smart Manager for WooCommerce
An authenticated SQL injection vulnerability in the Smart Manager plugin for WordPress allows subscriber-level users to perform database exfiltration through the access_privileges parameter.
CVE search metadata
CVE search record: CVE-2026-18443. Severity: high. CVSS: 8.8. KEV: no. Product: Smart Manager for WooCommerce (<= 8.97.0). Brief: SQL Injection in Smart Manager for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-smart-manager-sql-injection/
The Smart Manager for WooCommerce plugin (versions 8.97.0 and below) contains a critical SQL injection vulnerability identified as CVE-2026-18443. The flaw exists due to inadequate input sanitization and lack of parameterized queries within the 'access_privileges' parameter handling logic. Attackers with at least subscriber-level access can manipulate database queries to exfiltrate sensitive information. This exploitation vector is specifically viable on installations where an administrator has configured a role-based deny-list for Access Privileges but failed to explicitly exclude the internal 'access-privilege' module. Because of this oversight, the authorization filter erroneously permits lower-privileged users to invoke the vulnerable handler, enabling unauthorized database interaction.
Impact
Successful exploitation allows authenticated attackers with subscriber-level access to execute arbitrary SQL commands against the underlying WordPress database. This can lead to the unauthorized extraction of sensitive business data, customer information, or administrative credentials stored within the WooCommerce environment. The vulnerability impacts all WordPress installations running the affected plugin versions where specific, non-restrictive access configurations are present.
Recommendation
- Upgrade the 'Smart Manager - Advanced WooCommerce Bulk Edit & Inventory Management' plugin to the latest version (above 8.97.0) immediately.
- Review role-based Access Privilege configurations in the Smart Manager dashboard to ensure the 'access-privilege' module is explicitly restricted for all non-administrative user roles.
- Audit database access logs and monitor for anomalous SQL syntax errors or query patterns originating from subscriber-level user sessions.
Immediate actions
Upgrade Smart Manager for WooCommerce to a version higher than 8.97.0
Mitigations
Review and restrict role-based Access Privileges in Smart Manager settings
CVE-2026-18443
Detection coverage 1
Detects CVE-2026-18443 Exploitation - SQL Injection via access_privileges
highDetects exploitation of CVE-2026-18443 by monitoring for SQL injection patterns in HTTP requests targeting the Smart Manager access_privileges handler
Detection queries are available on the platform. Get full rules →