Storeapps Smart Manager vulnerabilities
4 known vulnerabilities affecting storeapps/smart_manager.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-0566P3HIGHCVSS 7.2PoCfixed in 8.28.02024-02-12
CVE-2024-0566 [HIGH] CWE-89 CVE-2024-0566: The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter b
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
nvd
CVE-2026-45216P3HIGHCVSS 8.8≥ n/a, ≤ 8.85.02026-05-25
CVE-2026-45216 [HIGH] CWE-266 CVE-2026-45216: Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
This issue affects Smart Manager: from n/a through 8.85.0.
cvelistv5nvd
CVE-2025-22710P3HIGHCVSS 7.6≤ 8.52.02025-01-21
CVE-2025-22710 [HIGH] CWE-89 CVE-2025-22710: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0.
nvd
CVE-2024-49687P4MEDIUMCVSS 4.3≤ 8.45.02024-12-31
CVE-2024-49687 [MEDIUM] CWE-862 CVE-2024-49687: Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This
Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0.
nvd