CVE-2023-2123

Severity
6.1MEDIUM
EPSS
15.7%
top 5.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 16
Latest updateSep 15

Description

The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site Scripting2023-08-16
GHSA
GHSA-4jpf-859w-v9gv: The WP Inventory Manager WordPress plugin before 22023-08-16

📋Vendor Advisories

1
Red Hat
kernel: coresight: Fix memory leak in acpi_buffer->pointer2025-09-15
CVE-2023-2123 (MEDIUM CVSS 6.1) | The WP Inventory Manager WordPress | cvebase.io