PatchSiren cyber security CVE debrief
CVE-2026-14203 Smart Manager CVE debrief
The Smart Manager WordPress plugin before version 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid. This allows users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. The vulnerability has a high impact on WordPress installations using the Smart Manager plugin, as it can lead to JavaScript injection attacks. Administrators should update the plugin to version 8.92.0 or later to mitigate this vulnerability.
- Vendor
- Smart Manager
- Product
- Smart Manager
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Administrators of WordPress installations using the Smart Manager plugin, security teams monitoring for potential JavaScript injection attacks, and users with the Contributor role or above should be aware of this vulnerability. They should update the plugin to version 8.92.0 or later, monitor for suspicious activity, and restrict Contributor role or above users to minimize potential attack surface.
Technical summary
The Smart Manager WordPress plugin before version 8.92.0 is vulnerable to JavaScript injection. An attacker with the Contributor role or above can inject malicious JavaScript code into a post field, which is then rendered in the management grid without proper encoding. When an administrator views the grid, the injected JavaScript code executes in their browser session. This vulnerability can be exploited by users with the Contributor role or above, and it has a high impact on WordPress installations using the Smart Manager plugin.
Defensive priority
High priority for WordPress administrators and security teams to update the Smart Manager plugin to version 8.92.0 or later and monitor for suspicious activity.
Recommended defensive actions
- Update the Smart Manager plugin to version 8.92.0 or later.
- Monitor for suspicious activity in the WordPress management grid.
- Restrict Contributor role or above users to minimize potential attack surface.
- Implement Content Security Policy (CSP) to mitigate JavaScript injection attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
Evidence is limited; primary official records indicate a vulnerability exists in the Smart Manager WordPress plugin before version 8.92.0. Further verification is needed to determine the full scope of affected systems and potential impact. Defenders should verify the plugin version, review management grid configurations, and monitor for suspicious activity. The CVE record was published on 2026-07-27T07:16:25.607Z and has not been modified since then.
Official resources
-
CVE-2026-14203 CVE record
CVE.org
-
CVE-2026-14203 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T07:16:25.607Z and has not been modified since then.