WordPress security by component
Smart Manager
Plugin description
Smart Manager is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.2.
Plugin slug:
smart-managerLatest vulnerability
CVE-2026-14203: Smart Manager post fields permit contributor stored XSS
Smart Manager before 8.92.0 lets a Contributor store attacker-controlled markup in a post field that is later rendered inside an HTML attribute in the management grid. The payload executes when an administrator or other privileged user views the affected grid row. The CNA record does not identify the post field, request parameter or rendering function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-14203
Smart Manager post fields permit contributor stored XSS
Smart Manager before 8.92.0 lets a Contributor store attacker-controlled markup in a post field that is later rendered inside an HTML attribute in the management grid. The payload executes when an administrator or other privileged user views the affected grid row. The CNA record does not identify the post field, request parameter or rendering function.
|
8.92.0 |
CVE4.8
NVDPending
|
| Feb 12, 2024 |
CVE-2024-0566
Smart Manager: SQL injection
Smart Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|