vendor:
Wordpress Sliced Invoices
by:
Lucian Ioan Nitescu
5.5
CVSS
MEDIUM
SQL Injection
89
CWE
Product Name: Wordpress Sliced Invoices
Affected Version From: Lower than 3.8.2
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:slicedinvoices:wordpress_sliced_invoices:3.8.2
Platforms Tested: Ubuntu 18.04 / Wordpress 5.3
2019
WordPress Sliced Invoices 3.8.2 – ‘post’ SQL Injection
Wordpress Sliced Invoices plugin with a version lower than 3.8.2 is affected by an Authenticated SQL Injection vulnerability.
Mitigation:
Update to version 3.8.2 or higher.