« Back to list

Usabilitydynamics

Usabilitydynamics Wp-invoice: vulnerabilities and CVEs

Usabilitydynamics Wp-invoice has 7 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-1617Medium (6.1)0.27%—Jan 16, 2024
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin…
CVE-2016-11011Medium (6.5)1.4%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
CVE-2016-11010Medium (5.3)1.8%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
CVE-2016-11009Medium (5.3)1.8%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
CVE-2016-11008Medium (5.3)1.8%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
CVE-2016-11007Medium (5.3)2.0%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
CVE-2016-11006Medium (5.3)1.8%—Sep 20, 2019
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.

Other products by Usabilitydynamics