Ghostwire

CVE-2026-14203: The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML...

MEDIUM CVSS 0.0

Published: July 27, 2026 | Last Modified: July 27, 2026

Description

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References