cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forsmart-manager-for-wp-e-commerce smart-manager-for-wp-e-commerce

Direction: ascending
Jun 07, 2024

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2024-0566

CVE, Research URL

CVE-2024-0566

Date
Feb 12, 2024
Research Description
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Affected versions
max 8.28.0.
Status
vulnerable

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 54ee094a291c85ad46e95bf98a3a744d98443fda

Date
Jul 08, 2015
Research Description
Smart Manager &#8211; Advanced WooCommerce Bulk Edit &amp; Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 WordPress Smart Manager Plugin <= 3.9.6 - SQL Injection Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands. Update the plugin.
Affected versions
max 3.9.7.
Status
vulnerable
Oct 24, 2024

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2024-49687

CVE, Research URL

CVE-2024-49687

Date
Dec 31, 2024
Research Description
Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0.
Affected versions
max 8.46.0.
Status
vulnerable
Jan 19, 2025

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2025-22710

CVE, Research URL

CVE-2025-22710

Date
Jan 21, 2025
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
Affected versions
max 8.53.0.
Status
vulnerable
May 21, 2026

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2026-45216

CVE, Research URL

CVE-2026-45216

Date
May 26, 2026
Research Description
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.
Affected versions
max 8.86.0.
Status
vulnerable
Jun 16, 2026

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 0130d9d960becf1b24a092f970d0cb982b694506

Date
Jul 08, 2023
Research Description
Smart Manager &#8211; Advanced WooCommerce Bulk Edit &amp; Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 WordPress Smart Manager Plugin <= 3.9.6 is vulnerable to SQL Injection Update the plugin. Marcin Probola discovered and reported this SQL Injection vulnerability in WordPress Smart Manager Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.9.7.
Affected versions
max 3.9.7.
Status
vulnerable

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # e060fbff-792f-4fb5-baa5-82d80240ec99

Date
-
Research Description
Smart Manager &#8211; Advanced WooCommerce Bulk Edit &amp; Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 Smart Manager for WooCommerce &amp; WPeC &lt;= 3.9.6 - Unauthenticated SQL Injection The Smart Manager For WooCommerce &ndash; Stock Management, Bulk Edit &amp; more&hellip; WordPress plugin was affected by an Unauthenticated SQL Injection security vulnerability.
Affected versions
max 3.9.7.
Status
vulnerable

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 90d2e667232d387616c97d2bd492c2bc0fcc5194

Date
Jul 08, 2015
Research Description
Smart Manager &#8211; Advanced WooCommerce Bulk Edit &amp; Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 Smart Manager For WooCommerce < 3.9.7 - Unauthenticated SQL Injection The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ parameter in versions before 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 3.9.7.
Status
vulnerable
Jul 28, 2026
Jul 30, 2026

Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2026-14203

CVE, Research URL

CVE-2026-14203

Date
Jul 27, 2026
Research Description
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
Affected versions
max 8.92.0.
Status
vulnerable