Wpinventory's vulnerability footprint centers on its WordPress inventory management plugin, a niche asset-tracking tool for WordPress environments. The recurring exposure centers on cross-site request forgery weaknesses, a class endemic to web applications that accept state-changing requests without proper token validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpinventory over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57772HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Inject | Jul 13, 2026 | 8.5 | 35 | NO | NO |
CVE-2023-34002HIGH Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory Manager plugin <= 2.1.0.13 versions. | Nov 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-2123MEDIUM The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scriptin | Aug 16, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-2842HIGH The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack | Jun 27, 2023 | 8.1 | 20 | NO | NO |
CVE-2023-1806MEDIUM The WP Inventory Manager WordPress plugin before 2.1.0.12 does not sanitise and escape the message parameter before outputting it back in the page, leading to a Reflected Cross-Sit | May 8, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-49977MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: | Jun 20, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpinventory.
Media articles that mention a CVE ID that affects a product developed by Wpinventory — matched by CVE ID, not by vendor name.