Executive brief
Smart Manager is a WordPress plugin used by e-commerce sites to manage products, customers, and orders. A security flaw allows attackers to inject malicious scripts into the website, which could lead to unauthorized actions or data theft when an administrator visits a specific page. This could result in the compromise of the site's management interface or the redirection of customers to malicious websites.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Smart Manager for WooCommerce plugin (versions <= 8.90.0) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is unauthenticated, meaning an attacker does not need an account on the target site to initiate the attack. However, successful exploitation requires user interaction, typically involving a privileged user clicking a specially crafted link. Once executed, the malicious script runs in the context of the victim's browser, potentially allowing for session hijacking or administrative actions. The issue is resolved in version 8.91.0.
Affected products
- StoreApps Smart Manager for WooCommerce <= 8.90.0
Timeline
- 2026-06-18: other: Reported by Nguyen Ba Khanh
- 2026-07-20: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date