Stock Manager for WooCommerce [woocommerce-stock-manager] < 3.6.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through < 3.6.0.
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jan 22, 2026
CVE-2026-24365 on NVD →
Stock Manager for WooCommerce < 3.6.0 - Cross-Site Request Forgery
medium
The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.6.0 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a...
- CVSS:
- 4.3
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
- Disclosed:
- Jan 9, 2026
CVE-2026-24365 on NVD →
Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.11.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.0
- Disclosed:
- Jul 11, 2023
CVE-2023-35091 on NVD →
Stock Manager for WooCommerce <= 2.10.0 - Cross-Site Request Forgery
medium
The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.0. This is due to missing nonce validation on the stock-manager-setting page. This makes it possible for unauthenticated attackers to enable old plugin styles via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.0
- Disclosed:
- Jun 14, 2023
CVE-2023-35091 on NVD →
Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.11.0
unknown
The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.0. This is due to missing nonce validation on the stock-manager-setting page. This makes it possible for unauthenticated attackers to enable old plugin styles via a forged request gr...
- Affected:
- up to 2.11.0
- Fixed in:
- 2.11.0
- Disclosed:
- Jun 14, 2023
Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.6.0
unknown
[en] The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.0
- Disclosed:
- Jul 21, 2021
CVE-2021-34619 on NVD →
WooCommerce Stock Manager <= 2.5.7 - Cross-Site Request Forgery to Arbitrary File Upload
high
The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.
- CVSS:
- 8.8
- Affected:
- up to 2.5.7
- Fixed in:
- 2.6.0
- Disclosed:
- Jun 14, 2021
CVE-2021-34619 on NVD →
Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.8
unknown
In the function function stock_manager_save_one_product_stock_data(), doesn't check for user capabilities so any logged in user can change the settings.
Update the plugin.
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Jul 27, 2017
WooCommerce Stock Manager < 1.0.9 - Authorization Bypass
high
The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stock_manager_table_variation_td function in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers to edit or delete products.
- CVSS:
- 8.8
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Jul 25, 2016
Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.8
unknown
The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stock_manager_table_variation_td function in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers to edit or delete products.
- Affected:
- up to 1.0.8
- Fixed in:
- 1.0.8
- Disclosed:
- Jul 25, 2016
Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.9
unknown
Missing CSRF and Authorisation checks in the stock_manager_save_one_product_stock_data() method registered as an AJAX call.
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database