Extension WordPress
Vulnérabilités Sliced Invoices – WordPress Invoice Plugin
Cette page rassemble les failles publiées pour Sliced Invoices – WordPress Invoice Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Sliced Invoices – WordPress Invoice Plugin
4 fiches
Sliced Invoices <= 3.9.5 – Missing Authorization
The Sliced Invoices – WordPress Invoice Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.9.5. This makes it possible for unauthenticated…
*-3.9.5
Non indiqué
31/03/2025
Sliced Invoices <= 3.9.2 – Missing Authorization
The Sliced Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the sure_to_email() function in versions up to, and including, 3.9.2. This makes it possible for authenticated attackers, with subscriber-level access…
*-3.9.2
3.9.3
28/03/2024
Sliced Invoices <= 3.8.2 – Reflected Cross-Site Scripting
The Sliced Invoices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-3.8.2
3.8.3
22/10/2019
Sliced Invoices < 3.8.4 – Authenticated SQL Injection
Sliced Invoices plugin for WordPress 3.8.3 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
[*, 3.8.4)
3.8.4
17/10/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.