Sliced Invoices – WordPress Invoice Plugin <= 3.8.2 - Authenticated (Contributor+) SQL Injection
medium
The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.5
- Affected:
- up to 3.8.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 15, 2026
CVE-2019-25746 on NVD →
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.9.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in SlicedInvoices Sliced Invoices. This issue affects Sliced Invoices: from n/a through 3.9.4.
- Affected:
- up to 3.9.5
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31628 on NVD →
Sliced Invoices <= 3.9.5 - Missing Authorization
medium
The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.9.5
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2025
CVE-2025-31628 on NVD →
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.9.3
unknown
[en] Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.3
- Disclosed:
- Jun 9, 2024
CVE-2024-30517 on NVD →
Sliced Invoices <= 3.9.2 - Missing Authorization
medium
The Sliced Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sure_to_email() function in versions up to, and including, 3.9.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails.
- CVSS:
- 4.3
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.3
- Disclosed:
- Mar 28, 2024
CVE-2024-30517 on NVD →
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.17
unknown
Authenticated SQL Injection (SQLi) vulnerability discovered by WordFence in WordPress Sliced Invoices plugin (versions <= 3.8.16).
- Affected:
- up to 3.8.17
- Fixed in:
- 3.8.17
- Disclosed:
- Dec 17, 2021
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.4
unknown
[en] Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Aug 31, 2020
CVE-2020-20625 on NVD →
Sliced Invoices <= 3.8.2 - Reflected Cross-Site Scripting
medium
The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Oct 22, 2019
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.3
unknown
The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Oct 22, 2019
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.4
unknown
Multiple vulnerabilities found by Jerome Bruandet (NinTechNet) in WordPress Sliced Invoices plugin (versions <= 3.8.2).
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Oct 18, 2019
Sliced Invoices < 3.8.4 - Authenticated SQL Injection
high
Sliced Invoices plugin for WordPress 3.8.3 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
- CVSS:
- 7.5
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Oct 17, 2019
CVE-2020-20625 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database