cleantalk
Vulnerabilities and Security Researches

WP Inventory Manager, CVE-2023-1806

CVE, Research URL

CVE-2023-1806

Application

WP Inventory Manager

Published on
May 08, 2023
Research Description
The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrators.
Affected versions
Min -, max 2.1.0.12.
Status
vulnerable