WordPress Smart Manager是WordPress基金会的一款高级 WooCommerce 批量编辑和库存管理插件。 WordPress Smart Manager 8.92.0之前版本存在跨站脚本漏洞,该漏洞源于对post字段编码不当,导致具有贡献者及以上角色的用户注入JavaScript,在管理员浏览器会话中执行跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Smart Manager | < 8.92.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Smart Manager | 0 ~ 8.92.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | |
| CVE-2026-14820 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via | |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | |
| CVE-2026-9830 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering v | |
| CVE-2026-14568 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion | |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| CVE-2026-14289 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution | |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Do | |
| CVE-2026-13597 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover | |
| CVE-2026-13726 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode | |
| CVE-2026-13714 | Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upl | |
| CVE-2026-10082 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcod | |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer | |
| CVE-2026-13332 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Serv | |
| CVE-2026-13390 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulati | |
| CVE-2026-13152 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escal | |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | |
| CVE-2026-12255 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordles | |
| CVE-2026-12394 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet