plugin

Invoicing Vulnerabilities

5 known security issues reported for the Invoicing WordPress plugin. Most recent disclosed Jul 31, 2026.

5 medium

Running Invoicing on your site? Check whether your installed version is affected.

Scan your site free

Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.56 - Authenticated (Administrator+) Local File Inclusion via Payment Form 'type' Element Field

medium

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.56 via the getpaid_payment_form_element function. This makes it possible for authenticated attackers, with administrator-level access and above, to incl...

CVSS:
6.6
Affected:
up to 2.8.56
Fixed in:
2.8.57
Disclosed:
Jul 31, 2026

CVE-2026-17605 on NVD →

GetPaid <= 2.8.54 - Unauthenticated Payment Bypass

medium

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 2.8.54. This is due to improper IPN verification. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 2.8.54
Fixed in:
2.8.55
Disclosed:
Jul 13, 2026

CVE-2026-12901 on NVD →

Payment forms, Buy now buttons, and Invoicing System | GetPaid <= 2.8.49 - Unauthenticated Information Exposure

medium

The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.49. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 2.8.49
Fixed in:
2.8.50
Disclosed:
Jun 8, 2026

CVE-2026-49064 on NVD →

GetPaid <= 2.8.11 - Missing Authorization via column_subscription()

medium

The GetPaid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the column_subscription() function in versions up to, and including, 2.8.11. This makes it possible for authenticated attackers, with contributor-level access and above, to access backend pages from the pl...

CVSS:
4.3
Affected:
up to 2.8.11
Fixed in:
2.8.12
Disclosed:
Aug 28, 2024

CVE-2024-43973 on NVD →

WordPress Payments Plugin | GetPaid <= 2.3.3 - Authenticated Stored Cross-Site Scripting

medium

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which i...

CVSS:
5.4
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Jun 2, 2021

CVE-2021-24369 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database