The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/8378 | third party advisory |
https://wordpress.org/plugins/wp-invoice/#developers | third party advisory release notes |
http://www.pritect.net/blog/wp-invoice-4-1-1-security-vulnerabilities | third party advisory exploit |