Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20625
Reference (s):
- https://blog.nintechnet.com/multiple-vulnerabilities-in-sliced-invoices-plugin/

