Vulnerabilities and security researches forsmart-manager-for-wp-e-commerce smart-manager-for-wp-e-commerce
Direction: descendingSmart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2026-14203
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jul 27, 2026
- Research Description
- The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
- Affected versions
-
max 8.92.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2026-57704
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jul 23, 2026
- Research Description
- Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
- Affected versions
-
max 8.91.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 0130d9d960becf1b24a092f970d0cb982b694506
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jul 08, 2023
- Research Description
- Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 WordPress Smart Manager Plugin <= 3.9.6 is vulnerable to SQL Injection Update the plugin. Marcin Probola discovered and reported this SQL Injection vulnerability in WordPress Smart Manager Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 3.9.7.
- Affected versions
-
max 3.9.7.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # e060fbff-792f-4fb5-baa5-82d80240ec99
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- -
- Research Description
- Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 Smart Manager for WooCommerce & WPeC <= 3.9.6 - Unauthenticated SQL Injection The Smart Manager For WooCommerce – Stock Management, Bulk Edit & more… WordPress plugin was affected by an Unauthenticated SQL Injection security vulnerability.
- Affected versions
-
max 3.9.7.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 90d2e667232d387616c97d2bd492c2bc0fcc5194
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jul 08, 2015
- Research Description
- Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 Smart Manager For WooCommerce < 3.9.7 - Unauthenticated SQL Injection The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ parameter in versions before 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 3.9.7.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2026-45216
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- May 26, 2026
- Research Description
- Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.
- Affected versions
-
max 8.86.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2025-22710
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jan 21, 2025
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
- Affected versions
-
max 8.53.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2024-49687
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Dec 31, 2024
- Research Description
- Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0.
- Affected versions
-
max 8.46.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # CVE-2024-0566
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Feb 12, 2024
- Research Description
- The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected versions
-
max 8.28.0.
- Status
-
vulnerable
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) # 54ee094a291c85ad46e95bf98a3a744d98443fda
- CVE, Research URL
- Home page URL
- Application
-
Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced)
- Date
- Jul 08, 2015
- Research Description
- Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management [smart-manager-for-wp-e-commerce] < 3.9.7 WordPress Smart Manager Plugin <= 3.9.6 - SQL Injection Because of this vulnerability, unauthenticated remote attackers can execute arbitrary SQL commands. Update the plugin.
- Affected versions
-
max 3.9.7.
- Status
-
vulnerable