Vendor
An authenticated SQL injection vulnerability in the Smart Manager plugin for WordPress allows subscriber-level users to perform database exfiltration through the access_privileges parameter.