<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:storeapps:smart_manager_for_woocommerce:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3astoreappssmart_manager_for_woocommercewordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3astoreappssmart_manager_for_woocommercewordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SQL Injection in Smart Manager for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-10-smart-manager-sql-injection/</link><pubDate>Sat, 03 Oct 2026 08:54:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-smart-manager-sql-injection/</guid><description>An authenticated SQL injection vulnerability in the Smart Manager plugin for WordPress allows subscriber-level users to perform database exfiltration through the access_privileges parameter.</description><content:encoded><![CDATA[<p>The Smart Manager for WooCommerce plugin (versions 8.97.0 and below) contains a critical SQL injection vulnerability identified as CVE-2026-18443. The flaw exists due to inadequate input sanitization and lack of parameterized queries within the 'access_privileges' parameter handling logic. Attackers with at least subscriber-level access can manipulate database queries to exfiltrate sensitive information. This exploitation vector is specifically viable on installations where an administrator has configured a role-based deny-list for Access Privileges but failed to explicitly exclude the internal 'access-privilege' module. Because of this oversight, the authorization filter erroneously permits lower-privileged users to invoke the vulnerable handler, enabling unauthorized database interaction.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows authenticated attackers with subscriber-level access to execute arbitrary SQL commands against the underlying WordPress database. This can lead to the unauthorized extraction of sensitive business data, customer information, or administrative credentials stored within the WooCommerce environment. The vulnerability impacts all WordPress installations running the affected plugin versions where specific, non-restrictive access configurations are present.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the 'Smart Manager - Advanced WooCommerce Bulk Edit &amp; Inventory Management' plugin to the latest version (above 8.97.0) immediately.</li>
<li>Review role-based Access Privilege configurations in the Smart Manager dashboard to ensure the 'access-privilege' module is explicitly restricted for all non-administrative user roles.</li>
<li>Audit database access logs and monitor for anomalous SQL syntax errors or query patterns originating from subscriber-level user sessions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>