CVE-2026-9857: Invoice123 WordPress Plugin Authorization Bypass Vulnerability
The Invoice123 WordPress plugin contains a flaw that allows users with basic subscriber accounts to make unauthorized changes to critical invoice and payment settings. Specifically, attackers can replace the plugin's API key, reconfigure invoice settings, and modify tax rate information in WooCommerce—actions they should not be able to perform. This vulnerability affects all versions up to and including 1.7.0 and requires no special technical knowledge to exploit, only valid WordPress login credentials at the subscriber level or higher.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-862
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-10 / 2026-07-10
NVD description (verbatim)
The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the plugin's API key stored in wp_options, modify invoice plugin settings, and alter WooCommerce tax rate data in the wp_woocommerce_tax_rates table.
12 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-9857 is an authorization bypass vulnerability (CWE-862) in the Invoice123 WordPress plugin caused by insufficient capability verification on administrative functions. Authenticated users with subscriber-level privileges or above can invoke plugin actions without proper role-based access controls, allowing them to overwrite the API key stored in the wp_options table, modify plugin configuration parameters, and directly manipulate WooCommerce tax rate records in wp_woocommerce_tax_rates. The vulnerability requires authentication but no user interaction, resulting in a CVSS 3.1 score of 4.3 (Medium severity).
Business impact
Organizations relying on Invoice123 for payment processing face operational risk if subscriber accounts are compromised or misused. Unauthorized modification of API keys could disrupt invoice generation and payment flows; altered tax rates may cause incorrect billing and compliance issues; and unauthorized plugin settings changes could expose configuration details or disable security features. The impact is primarily integrity-focused—attackers cannot read sensitive data or disable the system, but they can corrupt its state and create financial or compliance problems that require investigation and remediation.
Affected systems
The vulnerability affects WordPress installations using the Invoice123 plugin in version 1.7.0 and all earlier versions. Impact is limited to sites where WooCommerce is active (for tax rate modification) and where subscriber or higher-privilege users have login access. The vulnerability does not affect the plugin in isolation on WordPress instances without WooCommerce integration for the tax rate component, though API key and settings manipulation remain possible.
Exploitability
This vulnerability has low technical complexity and requires only valid WordPress credentials at subscriber level or above. No user interaction, special tools, or advanced knowledge is required—a malicious or compromised subscriber account can immediately perform the unauthorized actions through standard WordPress admin interfaces or plugin API endpoints. The network-accessible nature and low barrier to exploitation make this a practical risk in environments where account security is not strictly controlled.
Remediation
Administrators must upgrade the Invoice123 plugin to a patched version released after July 10, 2026. Verify the patched version number against the official WordPress plugin repository and the vendor advisory. As an interim measure, restrict subscriber-level user accounts and regularly audit wp_options for unauthorized API key changes and review WooCommerce tax rate modification logs. Remove or disable subscriber accounts that are not actively used.
Patch guidance
Check the WordPress plugin repository for Invoice123 and upgrade to the latest available version, which should address the authorization bypass. The vendor released a patch following the July 10, 2026 publication date. Confirm the patched version explicitly fixes CWE-862 authorization checks in the plugin's settings and tax rate functions. Test the update in a staging environment before deployment to production. After patching, regenerate API keys and verify that subscriber-level users can no longer access sensitive plugin settings.
Detection guidance
Monitor wp_options table modifications, particularly changes to Invoice123 plugin keys and configuration values, using database auditing or WordPress security plugins. Track modifications to the wp_woocommerce_tax_rates table and correlate them with user accounts—unexpected changes by subscriber-level users warrant investigation. Review WordPress user access logs for subscriber accounts accessing admin pages related to invoicing or tax settings. Implement capability checking via WordPress security tools to identify which user roles can access restricted plugin functions.
Why prioritize this
Although the CVSS score is Medium (4.3), this vulnerability merits rapid patching because it enables low-privilege users to corrupt billing and tax data without detection. The lack of detection difficulty and low technical bar for exploitation mean that any compromise of a subscriber account—whether through phishing, password reuse, or social engineering—immediately creates risk. Organizations with high user turnover or shared WordPress environments should prioritize this patch.
Risk score, explained
The CVSS 3.1 score of 4.3 reflects low impact (integrity only, no confidentiality or availability loss), low attack complexity, and the requirement for low-privilege authentication. The score does not fully capture organizational risk in environments where subscriber accounts are numerous or poorly managed, or where invoice/tax accuracy directly affects financial reporting or compliance audits. Security teams should assess their own privilege management practices and adjust internal risk ratings accordingly.
Frequently asked questions
Do we need to patch immediately if no subscriber accounts are currently active?
No, but it is still recommended. An immediate patch is less critical if subscriber-level access is tightly restricted and regularly audited. However, the vulnerability remains exploitable if any subscriber account is created, reactivated, or compromised in the future. Patching removes the risk entirely and is a low-cost operation.
Can this vulnerability be exploited by unauthenticated users or through default WordPress credentials?
No. Exploitation requires valid WordPress credentials at subscriber level or higher. It does not work for unauthenticated users and does not involve WordPress default credentials. However, any legitimate subscriber account—including those given to content contributors, testers, or third-party integrators—can be abused.
Will upgrading the Invoice123 plugin affect my existing invoices or settings?
No. Patch updates to the Invoice123 plugin should preserve existing data and settings. Test the update in a staging environment first to verify compatibility with your WooCommerce version and any custom configurations. After patching, regenerate your API key as a precaution.
How can we identify if this vulnerability was exploited before we patch?
Review database audit logs or backup records for changes to wp_options (particularly Invoice123 API keys) and wp_woocommerce_tax_rates made by subscriber-level accounts between July 10, 2026 and the patch date. Check WordPress access logs for unusual subscriber activity in invoice or settings admin pages. If you lack audit logging, consult a WordPress forensics specialist.
This analysis is based on the CVE record published July 10, 2026, and publicly available vendor information current as of that date. The vulnerability details, affected versions, and patch availability are subject to change; verify current patch status directly with the WordPress plugin repository and the vendor's official security advisory before taking action. No known public exploits are currently documented for this vulnerability. This document is for informational purposes and does not constitute legal or compliance advice. Organizations should assess their own risk tolerance and compliance obligations when prioritizing patching. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2024-24709MEDIUMShareaholic Missing Authorization Vulnerability – Update Required
- CVE-2024-31435MEDIUMMissing Authorization in Inisev Social Media & Share Icons Plugin—Patch Guidance
- CVE-2024-33685MEDIUMMissing Authorization in Jegstudio Startupzy 1.1.1 – MEDIUM Severity Vulnerability
- CVE-2024-33909MEDIUMMissing Authorization in Avirtum iPages Flipbook – CVSS 5.3 Patch Guide