Zintory – Inventory Manager
Zintory – Inventory Manager has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 7.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Deserialization Of Untrusted Data.
Every one of the 3 issues recorded for Zintory – Inventory Manager has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Zintory – Inventory Manager is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-56291PlainInventory <= 3.1.6 - Unauthenticated PHP Object Injection
Read the full analysisVulnerability Records

Zintory – Inventory Manager
Author
plainware
Zintory is a flexible, easy-to-use inventory manager and asset tracking tool. It quickly adapts to your inventory flow thanks to configurable account and transaction types. Manage your stock effortlessly with Zintory right on your WordPress website. Features Inventory Management. Manage your inventory and check stock levels in real-time online. Act on low inventory and generate purchase orders to fill your stock. Track Transactions. Manage your sales, orders, deliveries, item movements. Reports. Monitor utilization for all your inventory at a glance or focus on specific items. Pro Version Features Duplicate transactions Quickly create new transactions based on previous ones. Statistics for every item View each inventory item’s total statistics: total sold, purchased, moved, average price. Transaction history View the complete history of any transaction with all the changes. Support Please contact us at zintory.com Author: Plainware Author URI: https://www.zintory.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C