SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14203

MEDIUM · CVSS 4.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Smart Manager WordPress plugin prior to version 8.92.0 is vulnerable due to improper encoding of a post field, enabling users with Contributor roles or higher to inject malicious JavaScript into an HTML attribute. This could lead to cross-site scripting (XSS) attacks, potentially compromising the browser session of any administrator who views the management grid. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14203
Severity
MEDIUM
CVSS
4.8
EPSS
0.14%
WordPress Java

Original NVD Description

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.