Description
The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelist. The resulting string is concatenated into a raw SELECT statement that is executed via $wpdb->get_results(). This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection allowing attackers with Contributor access to read or manipulate database contents
Action: Apply Update
AI Analysis

Impact

The WP Inventory Manager plugin contains a SQL Injection vulnerability in the ‘where’ attribute of the [wpinventory] shortcode. Insufficient escaping and the absence of prepared statements allow authenticated users with CONTRIBUTOR or higher roles to inject additional SQL into a raw SELECT query, enabling the extraction or alteration of sensitive data stored in the WordPress database.

Affected Systems

WordPress sites running the WP Inventory Manager plugin by chuck1982, versions up to and including 2.5.1.

Risk and Exploitability

The issue carries a CVSS score of 6.5, indicating a moderate impact. EPSS is under 1 %, implying a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and at least Contributor privileges, after which an attacker can append arbitrary SQL statements to the existing query and read or modify database content.

Generated by OpenCVE AI on September 19, 2026 at 20:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Inventory Manager to the latest available version (≥ 2.5.2).
  • If an update is not immediately available, disable or remove the plugin from the site.
  • Restrict Contributor-level access or enforce least privilege on users who can invoke the shortcode.

Generated by OpenCVE AI on September 19, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Chuck1982
Chuck1982 wp Inventory Manager
Wordpress
Wordpress wordpress
Vendors & Products Chuck1982
Chuck1982 wp Inventory Manager
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelist. The resulting string is concatenated into a raw SELECT statement that is executed via $wpdb->get_results(). This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Chuck1982 Wp Inventory Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T11:34:07.234Z

Reserved: 2026-07-27T16:53:49.573Z

Link: CVE-2026-17607

cve-icon Vulnrichment

Updated: 2026-09-18T11:33:33.408Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:17:00.303

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-17607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:28Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')