PatchSiren

Smart Manager CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Smart Manager CVE published 2026-07-27

CVE-2026-14203

The Smart Manager WordPress plugin before version 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid. This allows users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. The vulnerability has a high impact on WordPress installations using the Smart Manager plugin, [truncated]