Storeapps develops a suite of WordPress and WooCommerce extensions focused on e-commerce functionality, including affiliate management, inventory control, and authentication features that integrate directly into web storefronts. The recurring vulnerability surface centers on input-handling and authorization weaknesses—cross-site request forgery, SQL injection, cross-site scripting, and missing or bypassable authorization checks—typical of server-side web applications that process user input and manage access controls, and these issues have acquired public exploit tooling. Defenders should treat plugin updates from this vendor as part of their WooCommerce maintenance cycle, particularly for internet-exposed stores; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Storeapps over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-45216HIGH Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
This issue affects Smart Manager: from n/a through 8.85.0. | May 25, 2026 | 8.8 | 32 | NO | NO |
CVE-2024-0566HIGH The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by hig | Feb 12, 2024 | 7.2 | 32 | NO | YES |
CVE-2026-57704HIGH Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | Jul 23, 2026 | 7.1 | 29 | NO | NO |
CVE-2022-25649HIGH Multiple Improper Access Control vulnerabilities in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress. | Aug 5, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-34619HIGH The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing n | Jul 21, 2021 | 8.8 | 27 | NO | NO |
CVE-2023-5663HIGH The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on | Mar 13, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-35091HIGH Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions. | Jul 11, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-24365MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Mana | Jan 22, 2026 | 5.4 | 23 | NO | NO |
CVE-2025-22710HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injec | Jan 21, 2025 | 7.6 | 22 | NO | NO |
CVE-2022-36284MEDIUM Authenticated IDOR vulnerability in StoreApps Affiliate For WooCommerce premium plugin <= 4.7.0 at WordPress allows an attacker to change the PayPal email. WooCommerce PayPal Payme | Aug 5, 2022 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Storeapps.
Media articles that mention a CVE ID that affects a product developed by Storeapps — matched by CVE ID, not by vendor name.