CVE-2020-20625

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
31/08/2020
Last modified:
04/09/2020

Description

Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:slicedinvoices:sliced_invoices:3.8.2:*:*:*:*:wordpress:*:*