Invoice123

Invoice123 has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Invoice123 has a vendor fix available, so running the current release closes it.

All of these findings were reported by Benedictus Jovan (aillesiM). Invoice123 is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Invoice123 vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-9857

Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions

Read the full analysis

Vulnerability Records

1 records
Invoice123 banner
Latestv1.7.3
0.0(0)
0/100
Last Updated
2026-08-17 (7d ago)
Active Installs
400+
Downloads
15,269
Requires WP
5.5+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2022-05-05 (4y ago)

Install this free plugin into your WordPress website, and by linking it with Invoice123 (in Lithuanian – Sąskaita123), simplify your data management process. This tool is suitable for everyone conducting online business, regardless of the business format. Invoice123 offers seamless invoice automation and customer management for efficient online accounting. The Invoice123 system has turned the old-fashioned manual invoicing method into a digital process that’s four times faster, available online 24/7. We provide all the necessary tools, from various integrations to connections with accounting systems or e-commerce platforms, tax calculators and more. Invoice123 is everything businesses of various types need to make their accounting easy and straightforward. We look forward to seeing you on our platform at www.invoice123.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C