CVE-2026-97183 PUBLISHED

WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers

Assigner: WPScan
Reserved: 24.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email addresses, display names and profile details of all registered users.

Product Status

Vendor Unknown
Product WP-Invoice
Versions Default: unknown
  • affected from 0 to 4.3.1 (incl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE