PLUGIN SECURITY

Is Sliced Invoices safe?

A WordPress invoicing plugin for creating invoices and quotes. Online payments, manage clients, reports, exports, taxes & more.

What this plugin does

  • Slug: sliced-invoices
  • Author: SlicedInvoices
  • 5000+ active installs
  • 92/100 rating (117 reviews on wordpress.org)
  • 259885 all-time downloads
  • On WordPress.org since 2015-12-22

invioceinvoiceinvoicingpdf invoicequote

Maintenance status

  • Latest known version: 3.10.0
  • Last updated: 2026-08-20 11:29pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 5.5+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

4 known CVEs on file for Sliced Invoices. Reported between 2019 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25746 Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.8.2 (unfixed) High 7.1 < 3.8.2 3.8.2 2026-06-15 ✓ fixed in latest
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.10.0 (unfixed) Missing Authorization Medium 5.3 < 3.10.0 3.10.0 2025-03-31 ✓ fixed in latest
CVE-2024-30517 Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.9.3 Missing Authorization High 8.8 < 3.9.3 3.9.3 2024-03-28 ✓ fixed in latest
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.17 Unknown < 3.8.17 3.8.17 2021-12-17 ✓ fixed in latest
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.3 Unknown < 3.8.3 3.8.3 2019-10-22 ✓ fixed in latest
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.4 Unknown < 3.8.4 3.8.4 2019-10-18 ✓ fixed in latest
CVE-2020-20625 Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] < 3.8.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 3.8.4 3.8.4 2019-10-17 ✓ fixed in latest
CVE-2025-31628 Sliced Invoices <= 3.10.1 - Missing Authorization Unknown not specified no fix on file

How to fix it

Keep Sliced Invoices updated — 3.10.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

1 of the vulnerabilities above has no fixed version on file — there's no update that resolves it. Consider deactivating this plugin or switching to one of the alternatives below.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.