← back
CVE-2023-2579

InventoryPress <= 1.7 - Author+ Stored XSS

EPSS 1.1%
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
Affected products
Unknown · InventoryPress

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →