Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in WP Inventory Manager versions 2.5.4 and earlier. It allows an attacker to inject arbitrary JavaScript into responses that are rendered in a visitor's browser, enabling actions such as credential theft, session hijacking, defacement, or phishing campaigns. The flaw is rooted in improper sanitization of user‑supplied input, classified as CWE‑79.
Affected Systems
Affected systems are WordPress installations that use the WP Inventory plugin. The reach encompasses any site running WP Inventory Manager version 2.5.4 or older. No specific PHP or WordPress core versions are limited; the issue exists across all supported WordPress environments where the plugin is active.
Risk and Exploitability
The CVSS base score of 7.1 indicates moderate severity, and the vulnerability is listed as unauthenticated, meaning any visitor can exploit it via crafted requests to the plugin’s interface. The EPSS score is not currently available, and the flaw is not in the CISA KEV catalog. Because the vulnerability does not require authentication and relies on standard web requests, it can be exploited remotely by attackers with little effort.
OpenCVE Enrichment