Wpinventory Wp Inventory Manager vulnerabilities

4 known vulnerabilities affecting wpinventory/wp_inventory_manager.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-34002HIGHCVSS 8.8fixed in 2.1.0.142023-11-09
CVE-2023-34002 [HIGH] CWE-352 CVE-2023-34002: Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions. Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions.
nvd
CVE-2023-2123MEDIUMCVSS 6.1fixed in 2.1.0.132023-08-16
CVE-2023-2123 [MEDIUM] CWE-79 CVE-2023-2123: The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter b The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
nvd
CVE-2023-2842HIGHCVSS 8.1fixed in 2.1.0.142023-06-27
CVE-2023-2842 [HIGH] CWE-352 CVE-2023-2842: The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could all The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack
nvd
CVE-2023-1806MEDIUMCVSS 6.1fixed in 2.1.0.122023-05-08
CVE-2023-1806 [MEDIUM] CWE-79 CVE-2023-1806: The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message p The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
nvd