SQL Injection Vulnerability in Sliced Invoices Plugin for WordPress
CVE-2019-25746
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 15 June 2026
Badges
What is CVE-2019-25746?
The Sliced Invoices plugin for WordPress, version 3.8.2, is affected by an authenticated SQL injection vulnerability that enables attackers with valid credentials to craft malicious database queries. By manipulating the 'post' parameter during requests to the admin.php endpoint with an action=duplicate_quote_invoice, attackers can extract sensitive information or alter database records. This vulnerability poses significant risks if exploited, as it can allow unauthorized access to critical database content and management.
Affected Version(s)
Sliced Invoices 3.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved