Vulnerability CVE-2023-2579


Published: 2023-07-17

Description:
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/3cfcb8cc-9c4f-409c-934f-9f3f043de6fe
https://github.com/daniloalbuqrque/poc-cve-xss-inventory-press-plugin

Copyright 2026, cxsecurity.com

 

Back to Top