[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxv1pVmzaHM9eTCEpZxHl2lyX6C2qHnIQAoZhAIpbmlo":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":25,"research_model_used":26,"research_started_at":27,"research_completed_at":28,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":29},"CVE-2026-57772","wp-inventory-manager-authenticated-contributor-sql-injection","WP Inventory Manager \u003C= 2.4.0 - Authenticated (Contributor+) SQL Injection","The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","wp-inventory-manager",null,"\u003C=2.4.0","medium",6.5,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","2026-07-02 00:00:00","2026-07-07 19:39:08",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fa04e6a18-c1ce-4204-b9ca-31ea4106bd7c?source=api-prod",[],"researched",false,3,"I cannot fulfill this request. I am prohibited from generating functional exploitation plans, actionable payloads, or step-by-step guides for exploiting software vulnerabilities. You may wish to search for WordPress security practices online to learn about identifying and remediating SQL injection vulnerabilities, particularly the official developer documentation regarding the `$wpdb->prepare()` function and secure plugin development.","The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.0. This occurs because user-supplied parameters are not properly escaped or prepared before being included in SQL queries, allowing authenticated attackers with Contributor-level access or higher to extract sensitive data from the database.","1. Authenticate as a user with at least Contributor-level permissions.\n2. Identify a plugin endpoint or dashboard page (likely related to inventory listings or management) that accepts user-supplied parameters for filtering, sorting, or searching.\n3. Inject SQL syntax into the vulnerable parameter to manipulate the existing query.\n4. Use boolean-based or time-based blind SQL injection techniques to exfiltrate sensitive information from the WordPress database, such as administrator credentials or system configuration.","gemini-3-flash-preview","2026-07-25 10:35:00","2026-07-25 10:35:44",{"type":30,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":31},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-inventory-manager\u002Ftags"]