Usabilitydynamics
Usabilitydynamics Wp-invoice: vulnerabilities and CVEs
Usabilitydynamics Wp-invoice has 7 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1617 | Medium (6.1) | 0.27% | — | Jan 16, 2024 | The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin… |
| CVE-2016-11011 | Medium (6.5) | 1.4% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. |
| CVE-2016-11010 | Medium (5.3) | 1.8% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates. |
| CVE-2016-11009 | Medium (5.3) | 1.8% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates. |
| CVE-2016-11008 | Medium (5.3) | 1.8% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates. |
| CVE-2016-11007 | Medium (5.3) | 2.0% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval. |
| CVE-2016-11006 | Medium (5.3) | 1.8% | — | Sep 20, 2019 | The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. |