CVE-2023-2842

Severity
8.1HIGH
EPSS
0.1%
top 69.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27

Description

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-89r6-wrjm-5xx8: The WP Inventory Manager WordPress plugin before 22023-06-27
CVEList
WP Inventory Manager < 2.1.0.14 - Inventory Items Deletion via CSRF2023-06-27
CVE-2023-2842 (HIGH CVSS 8.1) | The WP Inventory Manager WordPress | cvebase.io