WP-Invoice – Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)
unknown
[en] The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them
- Affected:
- up to 4.3.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2024
CVE-2022-1617 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.3.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
high
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing nonce validation on the save settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malic...
- CVSS:
- 8.8
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Apr 27, 2022
CVE-2022-1617 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.3.2 (closed)
unknown
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing nonce validation on the save settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malic...
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.2
- Disclosed:
- Apr 27, 2022
WP-Invoice – Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)
unknown
Arbitrary Settings Update via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress WP-Invoice plugin (versions <= 4.3.1).
- Affected:
- up to 4.3.1
- Fix:
- No patched version reported
- Disclosed:
- Apr 27, 2022
WP-Invoice – Web Invoice and Billing [wp-invoice] <= 4.3.1 (closed)
unknown
Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability discovered by Mariam Tariq in WordPress WP-Invoice plugin (versions <= 4.3.1).
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.1
- Disclosed:
- Apr 27, 2022
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11006 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11011 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11008 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11009 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11010 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Sep 20, 2019
CVE-2016-11007 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Privilege Escalation
high
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
- CVSS:
- 8.8
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11011 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Unauthorized Settings Change
medium
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
- CVSS:
- 6.5
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11006 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization
medium
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_paypal payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11008 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization
medium
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_interkassa payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthentica...
- CVSS:
- 5.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11009 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization
medium
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_twocheckout payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthentic...
- CVSS:
- 5.3
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11010 on NVD →
WP-Invoice – Web Invoice and Billing <= 4.1.0 - Insecure Direct Object Reference
medium
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
- CVSS:
- 5.3
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
CVE-2016-11007 on NVD →
WP-Invoice – Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)
unknown
This plugin is prone to unauthorized setting changes, retrieving invoices of arbitrary users, updating previously invoiced users meta data and privilege escalation of logged in users.
Update the plugin.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 3, 2016
WP-Invoice – Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)
unknown
The plugin does not have CSRF check in place when updating its settings, which could allow attacker to make a logged in admin update them and change the minimum role allowed to access the plugin's features to subscriber for example, which would make invoices available to any authenticated users
- Affected:
- up to 4.3.1
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database