plugin

Woocommerce Stock Manager Vulnerabilities

11 known security issues reported for the Woocommerce Stock Manager WordPress plugin. Most recent disclosed Jan 22, 2026.

2 high 2 medium

Running Woocommerce Stock Manager on your site? Check whether your installed version is affected.

Scan your site free

Stock Manager for WooCommerce [woocommerce-stock-manager] < 3.6.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forgery.This issue affects Stock Manager for WooCommerce: from n/a through < 3.6.0.

Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Jan 22, 2026

CVE-2026-24365 on NVD →

Stock Manager for WooCommerce < 3.6.0 - Cross-Site Request Forgery

medium

The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.6.0 (exclusive). This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a...

CVSS:
4.3
Affected:
up to 3.6.0
Fixed in:
3.6.0
Disclosed:
Jan 9, 2026

CVE-2026-24365 on NVD →

Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.11.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <= 2.10.0 versions.

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Jul 11, 2023

CVE-2023-35091 on NVD →

Stock Manager for WooCommerce <= 2.10.0 - Cross-Site Request Forgery

medium

The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.0. This is due to missing nonce validation on the stock-manager-setting page. This makes it possible for unauthenticated attackers to enable old plugin styles via a forged request gr...

CVSS:
4.3
Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Jun 14, 2023

CVE-2023-35091 on NVD →

Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.11.0

unknown

The Stock Manager for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.10.0. This is due to missing nonce validation on the stock-manager-setting page. This makes it possible for unauthenticated attackers to enable old plugin styles via a forged request gr...

Affected:
up to 2.11.0
Fixed in:
2.11.0
Disclosed:
Jun 14, 2023

Stock Manager for WooCommerce [woocommerce-stock-manager] < 2.6.0

unknown

[en] The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

Affected:
up to 2.6.0
Fixed in:
2.6.0
Disclosed:
Jul 21, 2021

CVE-2021-34619 on NVD →

WooCommerce Stock Manager <= 2.5.7 - Cross-Site Request Forgery to Arbitrary File Upload

high

The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file.

CVSS:
8.8
Affected:
up to 2.5.7
Fixed in:
2.6.0
Disclosed:
Jun 14, 2021

CVE-2021-34619 on NVD →

Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.8

unknown

In the function function stock_manager_save_one_product_stock_data(), doesn't check for user capabilities so any logged in user can change the settings. Update the plugin.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Jul 27, 2017

WooCommerce Stock Manager < 1.0.9 - Authorization Bypass

high

The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stock_manager_table_variation_td function in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers to edit or delete products.

CVSS:
8.8
Affected:
up to 1.0.7
Fixed in:
1.0.8
Disclosed:
Jul 25, 2016

Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.8

unknown

The WooCommerce Stock Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stock_manager_table_variation_td function in versions up to, and including, 1.0.8. This makes it possible for authenticated attackers to edit or delete products.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Jul 25, 2016

Stock Manager for WooCommerce [woocommerce-stock-manager] < 1.0.9

unknown

Missing CSRF and Authorisation checks in the stock_manager_save_one_product_stock_data() method registered as an AJAX call.

Affected:
up to 1.0.9
Fixed in:
1.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database