PatchSiren

WP-Invoice CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP-Invoice CVE published 2026-10-11

CVE-2026-97183

The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email addresses, display names and profile details of all registered users. This vulnerability allows attackers to access sensitive user information without proper authorization, potentially leading to data breaches and una [truncated]