Cross-Site Request Forgery Vulnerability in Stock Manager for WooCommerce by WordPress
CVE-2026-24365

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 January 2026

What is CVE-2026-24365?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Stock Manager for WooCommerce plugin, allowing remote attackers to trick users into performing unauthorized actions. This vulnerability affects versions of the Stock Manager plugin prior to 3.6.0, posing a risk to site integrity and user safety. It is critical for users of affected versions to apply security patches or upgrades to protect their WooCommerce installations.

Affected Version(s)

Stock Manager for WooCommerce <= n/a

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arif Shaikh | Patchstack Bug Bounty Program
.