plugin

Wp Invoice Vulnerabilities

19 known security issues reported for the Wp Invoice WordPress plugin. Most recent disclosed Jan 16, 2024.

2 high 5 medium

Running Wp Invoice on your site? Check whether your installed version is affected.

Scan your site free

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)

unknown

[en] The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them

Affected:
up to 4.3.1
Fix:
No patched version reported
Disclosed:
Jan 16, 2024

CVE-2022-1617 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.3.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

high

The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing nonce validation on the save settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malic...

CVSS:
8.8
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Apr 27, 2022

CVE-2022-1617 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.3.2 (closed)

unknown

The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing nonce validation on the save settings function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malic...

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Apr 27, 2022

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)

unknown

Arbitrary Settings Update via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress WP-Invoice plugin (versions <= 4.3.1).

Affected:
up to 4.3.1
Fix:
No patched version reported
Disclosed:
Apr 27, 2022

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] <= 4.3.1 (closed)

unknown

Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability discovered by Mariam Tariq in WordPress WP-Invoice plugin (versions <= 4.3.1).

Affected:
up to 4.3.1
Fixed in:
4.3.1
Disclosed:
Apr 27, 2022

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11006 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11011 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11008 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11009 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11010 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

[en] The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Sep 20, 2019

CVE-2016-11007 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Privilege Escalation

high

The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.

CVSS:
8.8
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11011 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Unauthorized Settings Change

medium

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

CVSS:
6.5
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11006 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization

medium

The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_paypal payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11008 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization

medium

The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_interkassa payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthentica...

CVSS:
5.3
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11009 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Missing Authorization

medium

The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_twocheckout payment gateway handler in versions up to, and including, 4.1.0. This makes it possible for unauthentic...

CVSS:
5.3
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11010 on NVD →

WP-Invoice – Web Invoice and Billing <= 4.1.0 - Insecure Direct Object Reference

medium

The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.

CVSS:
5.3
Affected:
up to 4.1.0
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

CVE-2016-11007 on NVD →

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] < 4.1.1 (closed)

unknown

This plugin is prone to unauthorized setting changes, retrieving invoices of arbitrary users, updating previously invoiced users meta data and privilege escalation of logged in users. Update the plugin.

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 3, 2016

WP-Invoice &#8211; Web Invoice and Billing [wp-invoice] <= 4.3.1 (unfixed + closed)

unknown

The plugin does not have CSRF check in place when updating its settings, which could allow attacker to make a logged in admin update them and change the minimum role allowed to access the plugin&#039;s features to subscriber for example, which would make invoices available to any authenticated users

Affected:
up to 4.3.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database