Cross-Site Request Forgery Vulnerability in Stock Manager for WooCommerce by WordPress
CVE-2026-24365
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2026
What is CVE-2026-24365?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Stock Manager for WooCommerce plugin, allowing remote attackers to trick users into performing unauthorized actions. This vulnerability affects versions of the Stock Manager plugin prior to 3.6.0, posing a risk to site integrity and user safety. It is critical for users of affected versions to apply security patches or upgrades to protect their WooCommerce installations.
Affected Version(s)
Stock Manager for WooCommerce <= n/a
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arif Shaikh | Patchstack Bug Bounty Program