Unauthenticated Information Disclosure and SQL Injection in Sliced Invoices Plugin for WordPress
CVE-2020-20625

7.5HIGH

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
31 August 2020

What is CVE-2020-20625?

The Sliced Invoices plugin for WordPress prior to version 3.8.2 is susceptible to vulnerabilities that enable an attacker to gain unauthorized access to sensitive information. Specifically, it allows for unauthenticated information disclosure and can be exploited to perform authenticated SQL injection through the core/class-sliced.php file. These weaknesses can be leveraged by malicious actors to manipulate the database, potentially leading to further security breaches.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.