Description
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an unauthenticated cross‑site scripting flaw in WP Inventory Manager versions 2.5.4 and earlier. It allows an attacker to inject arbitrary JavaScript into responses that are rendered in a visitor's browser, enabling actions such as credential theft, session hijacking, defacement, or phishing campaigns. The flaw is rooted in improper sanitization of user‑supplied input, classified as CWE‑79.

Affected Systems

Affected systems are WordPress installations that use the WP Inventory plugin. The reach encompasses any site running WP Inventory Manager version 2.5.4 or older. No specific PHP or WordPress core versions are limited; the issue exists across all supported WordPress environments where the plugin is active.

Risk and Exploitability

The CVSS base score of 7.1 indicates moderate severity, and the vulnerability is listed as unauthenticated, meaning any visitor can exploit it via crafted requests to the plugin’s interface. The EPSS score is not currently available, and the flaw is not in the CISA KEV catalog. Because the vulnerability does not require authentication and relies on standard web requests, it can be exploited remotely by attackers with little effort.

Generated by OpenCVE AI on September 17, 2026 at 23:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to WP Inventory Manager version 2.5.5 or later, if available, to remove the XSS flaw.
  • If an immediate update is not possible, disable the WP Inventory Manager plugin or remove its vulnerable endpoints until a patch is applied.
  • Verify that the end‑user interface sanitizes all user input, or implement a Web Application Firewall rule to block malicious scripts from being executed in the plugin’s responses.

Generated by OpenCVE AI on September 17, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpinventory
Wpinventory wp Inventory Manager
Vendors & Products Wordpress
Wordpress wordpress
Wpinventory
Wpinventory wp Inventory Manager

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
Title WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpinventory Wp Inventory Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T19:21:22.345Z

Reserved: 2026-09-14T08:28:47.825Z

Link: CVE-2026-90887

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:22.914Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:52.733

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-90887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')