What is CVE-2026-14203?
CVE-2026-14203: The Smart Manager WordPress plugin before version 8.92.0 fails to properly encode a post field before rendering it in an HTML attribute within its management grid. This allows users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator viewing the grid (stored XSS). Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-14203: Smart Manager WordPress plaqini 8.92.0 versiyasından əvvəl bir post sahəsini HTML atributunda düzgün encode etmir. Bu, Contributor və yuxarı roluna malik istifadəçilərə idarəetmə panelində administratorun brauzerində icra olunan JavaScript kodu yeritməyə imkan verir (stored XSS). Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What WordPress user role is required to exploit CVE-2026-14203?
The Contributor role or above is required to exploit this vulnerability.
What security issue does CVE-2026-14203 cause in the Smart Manager plugin?
The vulnerability leads to a stored XSS attack in the admin dashboard.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.