SlicedInvoices Sliced Invoices
cpe:2.3:a:slicedinvoices:sliced_invoices:*:*:*:*:wordpress:*:*
- <= 3.9.5
A missing authorization vulnerability has been identified in the Sliced Invoices WordPress plugin, specifically in versions through 3.9.5. This vulnerability allows for insecure direct object references, which could enable a malicious actor to bypass authorization and access sensitive files or interact with the database.
Exploitation of this vulnerability could lead to unauthorized access to sensitive data or files, allowing for potential manipulation of database contents.
Users of the Sliced Invoices WordPress plugin should update to version 3.9.5 or later. For those unable to update, Patchstack offers a virtual patching service that can auto-mitigate this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.