WP Clinic
Log in Sign up

CVE · High

CVE-2019-25746 — Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.8.2 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25746 Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.8.2 (unfixed) High 7.1 < 3.8.2 3.8.2 2026-06-15

CVE-2019-25746

WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post' values to extract sensitive database information or modify data.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.