plugin

Sliced Invoices Vulnerabilities

11 known security issues reported for the Sliced Invoices WordPress plugin. Most recent disclosed Jun 15, 2026.

1 high 4 medium

Running Sliced Invoices on your site? Check whether your installed version is affected.

Scan your site free

Sliced Invoices – WordPress Invoice Plugin <= 3.8.2 - Authenticated (Contributor+) SQL Injection

medium

The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with co...

CVSS:
6.5
Affected:
up to 3.8.2
Fix:
No patched version reported
Disclosed:
Jun 15, 2026

CVE-2019-25746 on NVD →

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] <= 3.9.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in SlicedInvoices Sliced Invoices. This issue affects Sliced Invoices: from n/a through 3.9.4.

Affected:
up to 3.9.5
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31628 on NVD →

Sliced Invoices <= 3.9.5 - Missing Authorization

medium

The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.9.5
Fix:
No patched version reported
Disclosed:
Mar 31, 2025

CVE-2025-31628 on NVD →

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] < 3.9.3

unknown

[en] Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.

Affected:
up to 3.9.3
Fixed in:
3.9.3
Disclosed:
Jun 9, 2024

CVE-2024-30517 on NVD →

Sliced Invoices <= 3.9.2 - Missing Authorization

medium

The Sliced Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sure_to_email() function in versions up to, and including, 3.9.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary emails.

CVSS:
4.3
Affected:
up to 3.9.2
Fixed in:
3.9.3
Disclosed:
Mar 28, 2024

CVE-2024-30517 on NVD →

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] < 3.8.17

unknown

Authenticated SQL Injection (SQLi) vulnerability discovered by WordFence in WordPress Sliced Invoices plugin (versions <= 3.8.16).

Affected:
up to 3.8.17
Fixed in:
3.8.17
Disclosed:
Dec 17, 2021

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] < 3.8.4

unknown

[en] Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.

Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
Aug 31, 2020

CVE-2020-20625 on NVD →

Sliced Invoices <= 3.8.2 - Reflected Cross-Site Scripting

medium

The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Oct 22, 2019

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] < 3.8.3

unknown

The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 3.8.3
Fixed in:
3.8.3
Disclosed:
Oct 22, 2019

Sliced Invoices &#8211; WordPress Invoice Plugin [sliced-invoices] < 3.8.4

unknown

Multiple vulnerabilities found by Jerome Bruandet (NinTechNet) in WordPress Sliced Invoices plugin (versions <= 3.8.2).

Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
Oct 18, 2019

Sliced Invoices < 3.8.4 - Authenticated SQL Injection

high

Sliced Invoices plugin for WordPress 3.8.3 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.

CVSS:
7.5
Affected:
up to 3.8.4
Fixed in:
3.8.4
Disclosed:
Oct 17, 2019

CVE-2020-20625 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database