CVE-2026-90887: WordPress WP Inventory Manager plugin <= 2.5.4 - Cross Site Scripting (XSS) vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
Affected Software
1 affected component
wp-inventory-manager<=2.5.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Inventory Managerto a version that resolves this vulnerability.Fixed in 2.5.4
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WP Inventory Manager versions 2.5.4 and earlier are affected.
2
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need WordPress credentials.
3
Does exploiting this issue require user interaction?
Yes. The supplied CVSS vector includes UI:R, indicating user interaction is required for exploitation.