Review
Smart Manager
CVE published 2026-07-27
CVE-2026-14203
The Smart Manager WordPress plugin before version 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid. This allows users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. The vulnerability has a high impact on WordPress installations using the Smart Manager plugin, [truncated]