Input validation vulnerability in Smart Manager – WooCommerce Advanced Bulk Edit, Inventory Management & more… 3.9.7

The Smart Manager For WooCommerce plugin for WordPress is vulnerable to a security issue called blind SQL Injection. This happens when the plugin is used on versions before 3.9.7. The issue occurs because the plugin does not properly escape user-supplied information and also does not prepare the existing SQL query. This means an unauthenticated attacker can add additional SQL queries in the existing query which can be used to access sensitive information from the database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.