Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57704 2 Storeapps, Wordpress 2 Smart Manager, Wordpress 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
CVE-2024-49687 2 Storeapps, Wordpress 2 Smart Manager, Wordpress 2025-07-12 4.3 Medium
Missing Authorization vulnerability in StoreApps Smart Manager.This issue affects Smart Manager: from n/a through 8.45.0.
CVE-2024-0566 1 Storeapps 1 Smart Manager 2025-05-07 7.2 High
The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.