The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, making it vulnerable to SQL Injection attacks. Users with a role of contributor or higher can exploit this vulnerability.Creditspang0linReferenceshttps://github.com/pang0lin/CVEproject/blob/main/wordpress_Stock-in-and-out_sqli.mdhttps://wpscan.com/vulnerability/f903aadd-17af-4ddf-8635-abb3338ac815