← WordPress Vulnerabilities
WordPress security by component

Smart Manager

Smart Manager is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: smart-manager

CVE-2026-14203: Smart Manager post fields permit contributor stored XSS

Smart Manager before 8.92.0 lets a Contributor store attacker-controlled markup in a post field that is later rendered inside an HTML attribute in the management grid. The payload executes when an administrator or other privileged user views the affected grid row. The CNA record does not identify the post field, request parameter or rendering function.

PublishedJul 27, 2026
Known safe version8.92.0
Safe version
Jul 27, 2026 CVE-2026-14203
Smart Manager post fields permit contributor stored XSS
Smart Manager before 8.92.0 lets a Contributor store attacker-controlled markup in a post field that is later rendered inside an HTML attribute in the management grid. The payload executes when an administrator or other privileged user views the affected grid row. The CNA record does not identify the post field, request parameter or rendering function.
8.92.0
CVE4.8
NVDPending
Feb 12, 2024 CVE-2024-0566
Smart Manager: SQL injection
Smart Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2