Impact
The WP Inventory Manager plugin contains a SQL Injection vulnerability in the ‘where’ attribute of the [wpinventory] shortcode. Insufficient escaping and the absence of prepared statements allow authenticated users with CONTRIBUTOR or higher roles to inject additional SQL into a raw SELECT query, enabling the extraction or alteration of sensitive data stored in the WordPress database.
Affected Systems
WordPress sites running the WP Inventory Manager plugin by chuck1982, versions up to and including 2.5.1.
Risk and Exploitability
The issue carries a CVSS score of 6.5, indicating a moderate impact. EPSS is under 1 %, implying a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and at least Contributor privileges, after which an attacker can append arbitrary SQL statements to the existing query and read or modify database content.
OpenCVE Enrichment