The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0. This vulnerability allows authenticated attackers, with subscriber-level access and above, to append additional SQL queries into existing queries, potentially extracting sensitive informatio [truncated]
CVE-2026-45216 is a HIGH severity (CVSS 8.8) Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager, a WordPress plugin. The vulnerability allows authenticated attackers with low privileges to escalate their privileges, potentially gaining full administrative control. The issue affects all versions from n/a through 8.85.0. The vulnerability was published in the NVD on May 25, 2026, with a [truncated]