Sceawere

Vulnerability Detail

CVE-2026-97183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP-Invoice Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
8h ago
Vendor
Unknown
Product
WP-Invoice
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email addresses, display names and profile details of all registered users.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T07:17:29.707Z",
  "pubdate": "2026-10-11T07:17:29.707Z",
  "executiveSummary": "The WP-Invoice WordPress plugin, in versions up to and including 4.3.1, contains a critical Broken Access Control vulnerability residing within its AJAX request handling mechanism. This flaw stems from the total absence of capability checks within sensitive administrative AJAX endpoints.\nThe vulnerability allows any authenticated user—even those with the lowest possible privilege level, such as a Subscriber—to trigger server-side functions that are intended for administrative use only. By sending crafted AJAX requests to the vulnerable handlers, an attacker can bypass authorization protocols and retrieve sensitive internal data, including the email addresses, full display names, and comprehensive profile metadata of all registered users on the WordPress installation.\nThe impact is significant, as it facilitates mass user enumeration and information disclosure, which serves as a precursor to targeted phishing attacks, social engineering, or brute-force credential stuffing. Because the vulnerability requires only a valid user account on the affected WordPress site, the barrier to exploitation is extremely low, posing a high risk to user privacy and system security integrity.",
  "technicalDetails": "The root cause of this vulnerability is improper authorization enforcement within the WP-Invoice plugin's AJAX handler architecture. WordPress provides specific hooks (wp_ajax_*) for handling asynchronous requests; however, the plugin developers failed to implement necessary checks using current_user_can() or similar permission verification functions within the execution context of these specific handlers.\nIn a secure implementation, an AJAX handler should verify that the user associated with the active session possesses the required administrative capabilities (e.g., 'manage_options' or 'edit_users') before processing the request or returning database query results. In the vulnerable versions of WP-Invoice, these checks are omitted, effectively treating all authenticated requests as privileged.\nThe exploitation flow follows a straightforward trajectory. An attacker authenticated as a subscriber identifies the target AJAX action defined by the plugin. The attacker then constructs a POST request directed to /wp-admin/admin-ajax.php, including the action parameter associated with the vulnerable handler. Upon reception, the server executes the associated function without validating the requester's security context.\nSince the handler lacks authorization checks, it proceeds to perform database queries—likely targeting the wp_users or wp_usermeta tables—intended to fetch user information for the plugin's reporting or management interface. The handler then packages this sensitive data, which may include email addresses, hashed passwords (if exposed via meta), and custom user profile fields, into a JSON response sent back to the attacker's client.\nThis vulnerability is classified as an Insecure Direct Object Reference (IDOR) variant or a broader Broken Access Control issue within the WordPress context. Because the vulnerability is triggered via standard network protocols over HTTP/HTTPS, it is accessible from any location where the attacker can establish an authenticated session. The post-exploitation impact is primarily unauthorized information disclosure; however, the mass harvesting of user contact information represents a severe breach of data protection requirements and can be utilized for further lateral movement or platform compromise."
}
CVE-2026-97183: WP-Invoice Broken Access Control (MEDIUM Severity, CVSS: 4.3) | Sceawere