WordPress Plugin Vulnerabilities

Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title

Description

The plugin does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
TruongLV1 From FPT Nightwolf
Submitter
TruongLV1 From FPT Nightwolf
Verified
Yes

Timeline

Publicly Published
2026-07-06 (about 21 days ago)
Added
2026-07-06 (about 20 days ago)
Last Updated
2026-07-06 (about 20 days ago)

Other