The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.CreditsdaniloalbuqrqueWPScanReferenceshttps://wpscan.com/vulnerability/3cfcb8cc-9c4f-409c-934f-9f3f043de6fehttps://github.com/daniloalbuqrque/poc-cve-xss-inventory-press-plugin