Extension WordPress
Vulnérabilités WP-Invoice – Web Invoice and Billing
Cette page rassemble les failles publiées pour WP-Invoice – Web Invoice and Billing, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP-Invoice – Web Invoice and Billing
7 fiches
WP-Invoice – Web Invoice and Billing <= 4.3.1 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing nonce validation on the save settings function. This makes it…
*-4.3.1
4.3.2
27/04/2022
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Missing Authorization
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_paypal payment gateway handler in versions up to, and including,…
[*, 4.1.1)
4.1.1
03/02/2016
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Privilege Escalation
The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
[*, 4.1.1)
4.1.1
03/02/2016
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Missing Authorization
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_interkassa payment gateway handler in versions up to, and including,…
[*, 4.1.1)
4.1.1
03/02/2016
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Missing Authorization
The WP-Invoice – Web Invoice and Billing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpi_gateway_base::process_payment() function when using the wpi_twocheckout payment gateway handler in versions up to, and including,…
*-4.1.0
4.1.1
03/02/2016
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Insecure Direct Object Reference
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
*-4.1.0
4.1.1
03/02/2016
WP-Invoice – Web Invoice and Billing <= 4.1.0 – Unauthorized Settings Change
The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
*-4.1.0
4.1.1
03/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.