Executive brief
StoreApps Smart Manager is a WordPress plugin used by e-commerce store owners to manage products, customers, and orders in bulk. A security flaw in this plugin allows users with low-level access, such as contributors, to gain administrative control over the website. This could lead to unauthorized access to customer data, modification of store settings, or a complete takeover of the site.
Technical details
The StoreApps Smart Manager plugin for WordPress (versions up to 8.85.0) contains an Incorrect Privilege Assignment vulnerability (CWE-266). An attacker with a low-privileged account, such as a Contributor, can exploit this flaw to escalate their privileges to a higher level, potentially gaining full administrative access. The vulnerability is reachable over the network and does not require user interaction. This issue was addressed in version 8.86.0.
Affected products
- StoreApps Smart Manager for WooCommerce n/a through 8.85.0
Timeline
- 2026-03-09: other: Reported by Nguyen Ba Khanh
- 2026-05-12: advisory: Initial disclosure by Patchstack
- 2026-05-25: disclosed: NVD publication date
- 2026-05-12: patched: Version 8.86.0 released to address the issue