The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/8378 | third party advisory |
https://wordpress.org/plugins/wp-invoice/#developers | third party advisory release notes |
http://www.pritect.net/blog/wp-invoice-4-1-1-security-vulnerabilities | third party advisory exploit |