Security Advisory

CVE-2023-2842

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-27 13:17:17
Last updated 2024-11-27 19:22:40
Assigner WPScan
State PUBLISHED

Description

The WP Inventory Manager WordPress plugin before 2.1.0.14 does not have CSRF checks, which could allow attackers to make logged-in admins delete Inventory Items via a CSRF attack