Input validation vulnerability in WP-Invoice – Web Invoice and Billing 4.3.1

The WP-Invoice – Web Invoice and Billing plugin for WordPress has a security vulnerability that affects versions up to and including 4.3.1. This vulnerability allows unauthenticated attackers to make changes to the plugin’s settings and add malicious web scripts to the website without the site administrator’s knowledge. This happens because the save settings function does not contain any nonce validation which means attackers can forge requests and trick administrators into clicking on a link.

Detected in:

WP-Invoice – Web Invoice and Billing open vulnerable versions: >= * <= 4.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.