CVE-2026-97183: WP-Invoice <= 4.3.1 - Subscriber+ User PII Disclosure via Unprotected AJAX Handlers
Published Oct 11, 2026
·Updated
The WP-Invoice WordPress plugin through 4.3.1 does not perform capability checks in several of its AJAX handlers, allowing any authenticated user, such as a Subscriber, to retrieve the email addresses, display names and profile details of all registered users.
Affected Software
1 affected component
WP-Invoice<=4.3.1
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated WordPress user can exploit the affected AJAX handlers, including users with only the Subscriber role. An attacker does not need administrative privileges.
2
What information can be exposed?
The vulnerable handlers can disclose email addresses, display names, and profile details for all registered WordPress users.
3
Are unauthenticated visitors affected?
The available information identifies this as an authenticated-user issue. It does not state that unauthenticated visitors can access the exposed data.