Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.
Published: 2025-06-20
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) was found in the WP Inventory Manager plugin for WordPress. The plugin exposes endpoints that perform inventory actions without verifying that the request originated from the legitimate site, exposing a missing CSRF protection token. An attacker can trick an authenticated user into submitting a request to the plugin, which will then carry out inventory changes, such as adding, editing, or deleting items, under the user’s credentials. The flaw does not directly expose sensitive data but can compromise data integrity and potentially affect business operations that rely on accurate inventory records.

Affected Systems

WordPress installations that use the WP Inventory Manager plugin, version 2.3.4 or earlier. The vulnerability applies to all plugin versions up to and including 2.3.4, regardless of the host WordPress theme or other plugins. Users running these versions should verify the installed version and update accordingly.

Risk and Exploitability

The CVSS score of 4.3 indicates a low‑to‑moderate severity, and the EPSS score of less than 1% suggests a small probability of exploitation in the wild. However, because the attacker only needs a victim’s authenticated session cookie and a malicious link or form, the attack vector is readily achievable via phishing or malicious content injected into user‑facing pages. While the vulnerability is not listed in CISA’s KEV catalog, organizations that store critical inventory data should treat it as a valid concern, particularly if the WordPress instance is publicly exposed and users actively perform transaction tasks.

Generated by OpenCVE AI on April 30, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch for WP Inventory Manager 2.3.5 or later immediately.
  • If an immediate upgrade is not possible, disable the vulnerable inventory actions or remove the plugin until a safe version is deployed.
  • Use a web application firewall or security plugin to block POST requests to the plugin’s endpoints from untrusted origins, reducing the chance of successful CSRF attempts.

Generated by OpenCVE AI on April 30, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18946 Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager allows Cross Site Request Forgery. This issue affects WP Inventory Manager: from n/a through 2.3.4.
History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mylacventures WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4. Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4. Cross-Site Request Forgery (CSRF) vulnerability in mylacventures WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager allows Cross Site Request Forgery. This issue affects WP Inventory Manager: from n/a through 2.3.4. Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Cross Site Request Forgery.This issue affects WP Inventory Manager: from n/a through <= 2.3.4.
Title WordPress WP Inventory Manager plugin <= 2.3.4 - Cross Site Request Forgery (CSRF) Vulnerability WordPress WP Inventory Manager plugin <= 2.3.4 - Cross Site Request Forgery (CSRF) vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 23 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Inventory WP Inventory Manager allows Cross Site Request Forgery. This issue affects WP Inventory Manager: from n/a through 2.3.4.
Title WordPress WP Inventory Manager plugin <= 2.3.4 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:14.203Z

Reserved: 2025-06-11T16:07:48.985Z

Link: CVE-2025-49977

cve-icon Vulnrichment

Updated: 2025-06-23T20:52:08.801Z

cve-icon NVD

Status : Deferred

Published: 2025-06-20T15:15:23.277

Modified: 2026-04-28T19:33:17.410

Link: CVE-2025-49977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:45:26Z

Weaknesses