VendorsUsabilityDynamicswp-invoiceany version
Vulnerabilities

UsabilityDynamics WP-Invoice for WordPress any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2016-11011
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
Published 2019-09-20 · Modified
6.5EPSS 0.014
CVE-2022-1617
WP-Invoice <= 4.3.1 - Stored Cross-Site Scripting via CSRF
Published 2024-01-16 · Modified
6.1EPSS 0.003
CVE-2016-11007
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
Published 2019-09-20 · Modified
5.3EPSS 0.020
CVE-2016-11006
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
Published 2019-09-20 · Modified
5.3EPSS 0.018
CVE-2016-11008
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
Published 2019-09-20 · Modified
5.3EPSS 0.018
CVE-2016-11009
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates.
Published 2019-09-20 · Modified
5.3EPSS 0.018
CVE-2016-11010
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata updates.
Published 2019-09-20 · Modified
5.3EPSS 0.018