← Back

Web Invoice Project

web_invoice_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Web Invoice
web_invoice

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Web Invoice Project
1Web Invoice
Jun 17, 2026
Jan 2, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default...Show more
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as wellShow less