CyberRota Analysis
AI-GeneratedThe Smart Manager WordPress plugin prior to version 8.92.0 is vulnerable due to improper encoding of a post field, enabling users with Contributor roles or higher to inject malicious JavaScript into an HTML attribute. This could lead to cross-site scripting (XSS) attacks, potentially compromising the browser session of any administrator who views the management grid. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.