{"api_version":"1","generated_at":"2026-10-03T06:30:58+00:00","cve":"CVE-2026-17607","urls":{"html":"https://cve.report/CVE-2026-17607","api":"https://cve.report/api/cve/CVE-2026-17607.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-17607","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-17607"},"summary":{"title":"WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute","description":"The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelist. The resulting string is concatenated into a raw SELECT statement that is executed via $wpdb->get_results(). This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2026-09-18 08:17:00","updated_at":"2026-09-18 13:23:37"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[{"version":"3.1","source":"security@wordfence.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f439d60-0295-4ea8-b16d-9cdd0d866a8d?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f439d60-0295-4ea8-b16d-9cdd0d866a8d?source=cve","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L269","name":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L269","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L211","name":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L211","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/wpinventory.core.php#L448","name":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/wpinventory.core.php#L448","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3657730%40wp-inventory-manager&new=3657730%40wp-inventory-manager","name":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3657730%40wp-inventory-manager&new=3657730%40wp-inventory-manager","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L748","name":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L748","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.shortcode.class.php#L72","name":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.shortcode.class.php#L72","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-17607","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17607","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"chuck1982","product":"WP Inventory Manager","version":"affected 2.5.1 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-17T18:52:03.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Wordfence PRISM","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"17607","cve":"CVE-2026-17607","epss":"0.003430000","percentile":"0.279610000","score_date":"2026-09-20","updated_at":"2026-09-21 00:10:10"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-17607","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-18T11:32:05.220576Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-18T11:34:07.234Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP Inventory Manager","vendor":"chuck1982","versions":[{"lessThanOrEqual":"2.5.1","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Wordfence PRISM"}],"descriptions":[{"lang":"en","value":"The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelist. The resulting string is concatenated into a raw SELECT statement that is executed via $wpdb->get_results(). This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"metrics":[{"cvssV3_1":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T07:39:59.742Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/1f439d60-0295-4ea8-b16d-9cdd0d866a8d?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L269"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L748"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.item.class.php#L211"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/includes/wpinventory.shortcode.class.php#L72"},{"url":"https://plugins.trac.wordpress.org/browser/wp-inventory-manager/tags/2.4.1/wpinventory.core.php#L448"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3657730%40wp-inventory-manager&new=3657730%40wp-inventory-manager"}],"timeline":[{"lang":"en","time":"2026-09-17T18:52:03.000Z","value":"Disclosed"}],"title":"WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL Injection via 'where' Shortcode Attribute"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2026-17607","datePublished":"2026-09-18T07:39:59.742Z","dateReserved":"2026-07-27T16:53:49.573Z","dateUpdated":"2026-09-18T11:34:07.234Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 08:17:00","lastModifiedDate":"2026-09-18 13:23:37","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-18T11:32:05.220576Z","id":"CVE-2026-17607","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"17607","Ordinal":"1","Title":"WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL","CVE":"CVE-2026-17607","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"17607","Ordinal":"1","NoteData":"The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in the WPIMItem::get_all() function — parse_custom_where() only performs html_entity_decode(), strips semicolons, and does field-label name replacements, without using $wpdb->prepare() or a whitelist. The resulting string is concatenated into a raw SELECT statement that is executed via $wpdb->get_results(). This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","Type":"Description","Title":"WP Inventory Manager <= 2.5.1 - Authenticated (Contributor+) SQL"}]}}}