Cross-site Scripting Vulnerability in Easy Invoice by MatrixAddons
CVE-2025-6324
7.1HIGH
What is CVE-2025-6324?
A Cross-site Scripting (XSS) vulnerability in the Easy Invoice plugin by MatrixAddons allows attackers to inject malicious scripts into web pages viewed by users. This DOM-Based XSS risk affects versions up to and including 2.0.9, enabling potential exploitation scenarios that could compromise user data and security. Website owners using Easy Invoice should be aware and take preventive measures to ensure their installations are updated to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Easy Invoice <= n/a
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ryan Novotny | Patchstack Bug Bounty Program