天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-18443 Smart Manager WooCommerce 插件 SQL 注入漏洞

影响认证攻击者可注入 SQL 读取数据库敏感信息

AI 研判

WordPress 插件 Smart Manager(Advanced WooCommerce Bulk Edit & Inventory Management)在 8.97.0 及之前版本中存在通用 SQL 注入漏洞。漏洞位于 access_privileges 参数,因未充分转义用户输入且 SQL 查询未做预处理,攻击者可向既有查询追加恶意 SQL 语句。

影响范围

Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management

影响该插件所有版本至 8.97.0(含)。仅当管理员保存了基于角色的拒绝名单 Access Privilege 配置且未显式阻止内部 access-privilege 模块时,漏洞才可被利用。

漏洞详情

漏洞类型为通用 SQL 注入,成因是 access_privileges 参数缺乏转义与参数化查询。拥有订阅者及以上权限的认证用户可构造恶意输入,将额外 SQL 语句拼接到原查询中。利用成功后可提取数据库中的敏感信息。

利用条件与风险

利用前提是目标站点存在特定 Access Privilege 配置(管理员保存的拒绝名单未阻止 access-privilege 模块),且攻击者需具备订阅者及以上权限。实战中可导致数据库敏感数据泄露,风险较高。

修复建议

建议升级至官方修复版本(暂无公开信息确认具体版本号)。临时缓解措施:检查并调整 Access Privilege 配置,显式阻止内部 access-privilege 模块,或限制低权限用户访问相关功能。

原始情报

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the ‘access_privileges’ parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This exploit is only possible on installations where an administrator has saved a role-based deny-list Access Privilege configuration that does not explicitly block the internal ‘access-privilege’ module, as this condition allows the authorization filter to implicitly permit Subscriber-level users to invoke the vulnerable handler.