plugin

Smart Manager For Wp E Commerce Vulnerabilities

7 known security issues reported for the Smart Manager For Wp E Commerce WordPress plugin. Most recent disclosed Jul 20, 2026.

1 critical 3 high 3 medium

Running Smart Manager For Wp E Commerce on your site? Check whether your installed version is affected.

Scan your site free

Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management <= 8.90.0 - Unauthenticated Stored Cross-Site Scripting

high

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.90.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
7.2
Affected:
up to 8.90.0
Fixed in:
8.91.0
Disclosed:
Jul 20, 2026

CVE-2026-57704 on NVD →

Smart Manager <= 8.91.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Smart Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.91.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages t...

CVSS:
6.4
Affected:
up to 8.91.0
Fixed in:
8.92.0
Disclosed:
Jul 6, 2026

CVE-2026-14203 on NVD →

Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management <= 8.85.0 - Authenticated (Contributor+) Privilege Escalation

high

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 8.85.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to elevate their privileges to that of an admini...

CVSS:
8.8
Affected:
up to 8.85.0
Fixed in:
8.86.0
Disclosed:
May 12, 2026

CVE-2026-45216 on NVD →

Smart Manager <= 8.52.0 - Authenticated (Administrator+) SQL Injection

medium

The Smart Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.52.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access an...

CVSS:
4.9
Affected:
up to 8.52.0
Fixed in:
8.53.0
Disclosed:
Jan 15, 2025

CVE-2025-22710 on NVD →

Smart Manager <= 8.45.0 - Missing Authorization

medium

The Smart Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_to_pro() function in versions up to, and including, 8.45.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to upgrade the plugin to pro.

CVSS:
4.3
Affected:
up to 8.45.0
Fixed in:
8.46.0
Disclosed:
Oct 21, 2024

CVE-2024-49687 on NVD →

Smart Manager - WooCommerce Advanced Bulk Edit, Inventory Management & more... <= 8.27.0 - Authenticated (Admin+) SQL Injection

high

The Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) plugin for WordPress is vulnerable to SQL Injection via the 'sortOrder' parameter in all versions up to, and including, 8.27.0 due to insufficient escaping on the user supplied parameter and lack of sufficient prepar...

CVSS:
7.2
Affected:
up to 8.27.0
Fixed in:
8.28.0
Disclosed:
Jan 18, 2024

CVE-2024-0566 on NVD →

Smart Manager For WooCommerce < 3.9.7 - Unauthenticated SQL Injection

critical

The Smart Manager For WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via the ‘edited’ parameter in versions before 3.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers t...

CVSS:
9.8
Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jul 8, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database