Usabilitydynamics
Usabilitydynamics Wp-invoice: vulnerabilidades y CVE
Usabilitydynamics Wp-invoice tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1617 | Media (6.1) | 0.27% | — | 16 ene 2024 | The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin… |
| CVE-2016-11011 | Media (6.5) | 1.4% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. |
| CVE-2016-11010 | Media (5.3) | 1.8% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. |
| CVE-2016-11009 | Media (5.3) | 1.8% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. |
| CVE-2016-11008 | Media (5.3) | 1.8% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. |
| CVE-2016-11007 | Media (5.3) | 2.0% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. |
| CVE-2016-11006 | Media (5.3) | 1.8% | — | 20 sept 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. |