NA

CVE-2022-1617

Published: 16/01/2024 Updated: 23/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The WP-Invoice WordPress plugin up to and including 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing malicious user to make a logged in admin change them and add XSS payload in them

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

usabilitydynamics wp-invoice