Invoice123
Invoice123 has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Invoice123 has a vendor fix available, so running the current release closes it.
All of these findings were reported by Benedictus Jovan (aillesiM). Invoice123 is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-9857Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions
Read the full analysisVulnerability Records

Invoice123
Author
Invoice123
Install this free plugin into your WordPress website, and by linking it with Invoice123 (in Lithuanian – Sąskaita123), simplify your data management process. This tool is suitable for everyone conducting online business, regardless of the business format. Invoice123 offers seamless invoice automation and customer management for efficient online accounting. The Invoice123 system has turned the old-fashioned manual invoicing method into a digital process that’s four times faster, available online 24/7. We provide all the necessary tools, from various integrations to connections with accounting systems or e-commerce platforms, tax calculators and more. Invoice123 is everything businesses of various types need to make their accounting easy and straightforward. We look forward to seeing you on our platform at www.invoice123.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C