Wpinventory
Wpinventory WP Inventory Manager: vulnerabilidades y CVE
Wpinventory WP Inventory Manager tiene 9 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-17607 | Media (6.5) | 0.34% | — | 18 sept 2026 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient… |
| CVE-2026-90887 | Alta (7.1) | 0.25% | — | 17 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. |
| CVE-2026-57772 | Alta (8.5) | 0.36% | — | 13 jul 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory… |
| CVE-2025-49977 | Media (4.3) | 0.15% | — | 20 jun 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4. |
| CVE-2024-13434 | Media (6.1) | 0.29% | — | 17 ene 2025 | The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output… |
| CVE-2023-34002 | Alta (8.8) | 0.30% | — | 9 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions. |
| CVE-2023-2123 | Media (6.1) | 1.2% | — | 16 ago 2023 | The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. |
| CVE-2023-2842 | Alta (8.1) | 0.35% | — | 27 jun 2023 | The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack |
| CVE-2023-1806 | Media (6.1) | 0.46% | — | 8 may 2023 | The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.