Impact
Unauthenticated broken access control exists in WordPress Easy Invoice plugin versions up to 2.3.8, enabling an attacker to invoke privileged actions without valid credentials. The weakness permits bypassing the plugin’s intended authorisation checks, potentially allowing the creation, modification, or deletion of invoice records and related administrative operations. The vulnerability is classified as CWE‑862 and can compromise confidentiality, integrity, and availability of invoicing data.
Affected Systems
The plugin is distributed by MatrixAddons as "Easy Invoice". Any WordPress site running Easy Invoice 2.3.8 or older is affected. Up-to-date installations of 2.4.0 or newer are not vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the flaw is not listed in CISA KEV, suggesting a lower attack likelihood. Nevertheless, exploitation would require submitting unauthenticated requests to the plugin’s endpoints, which is feasible over the web interface or via crafted HTTP calls. Given the lack of authentication checks, a remote attacker could obtain full control over the invoicing subsystem without any additional credentials.
OpenCVE Enrichment