CVE-2026-18443 - Smart Manager <= 8.97.0 - Authenticated (Subscriber+) SQL Injection to Privilege Escalation via 'access_privileges' Parameter
CVE ID :CVE-2026-18443 Published : Oct. 3, 2026, 6:38 a.m. | 45 minutes ago Description :The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and...