Unauthenticated Information Disclosure and SQL Injection in Sliced Invoices Plugin for WordPress
CVE-2020-20625
7.5HIGH
What is CVE-2020-20625?
The Sliced Invoices plugin for WordPress prior to version 3.8.2 is susceptible to vulnerabilities that enable an attacker to gain unauthorized access to sensitive information. Specifically, it allows for unauthenticated information disclosure and can be exploited to perform authenticated SQL injection through the core/class-sliced.php file. These weaknesses can be leveraged by malicious actors to manipulate the database, potentially leading to further security breaches.