Junglewise Threat Intelligence

CVE-2026-45216: StoreApps Smart Manager privilege escalation

CVE-2026-45216 · Severity: high · CVSS 8.8 · Published 2026-05-25

Technologies: StoreApps Smart Manager for WooCommerce. Vendors: StoreApps.

Executive brief

StoreApps Smart Manager is a WordPress plugin used by e-commerce store owners to manage products, customers, and orders in bulk. A security flaw in this plugin allows users with low-level access, such as contributors, to gain administrative control over the website. This could lead to unauthorized access to customer data, modification of store settings, or a complete takeover of the site.

Technical details

The StoreApps Smart Manager plugin for WordPress (versions up to 8.85.0) contains an Incorrect Privilege Assignment vulnerability (CWE-266). An attacker with a low-privileged account, such as a Contributor, can exploit this flaw to escalate their privileges to a higher level, potentially gaining full administrative access. The vulnerability is reachable over the network and does not require user interaction. This issue was addressed in version 8.86.0.

Affected products

  • StoreApps Smart Manager for WooCommerce n/a through 8.85.0

Timeline

  • 2026-03-09: other: Reported by Nguyen Ba Khanh
  • 2026-05-12: advisory: Initial disclosure by Patchstack
  • 2026-05-25: disclosed: NVD publication date
  • 2026-05-12: patched: Version 8.86.0 released to address the issue

References

Related threats