Junglewise Threat Intelligence

CVE-2026-9857: saskaita123 Invoice123 authorization bypass in API and Invoice settings

CVE-2026-9857 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Executive brief

The Invoice123 plugin for WordPress, which handles automated invoicing and tax calculations, contains a security flaw that allows low-level users to change administrative settings. An attacker with a basic account (such as a subscriber) could overwrite the plugin's API key, modify invoice configurations, or alter WooCommerce tax rates. This could lead to financial discrepancies, disrupted billing operations, and unauthorized changes to how taxes are calculated on the site.

Technical details

The Invoice123 (saskaita123-lt) plugin for WordPress suffers from a missing authorization check (CWE-862) in several administrative functions. Specifically, the components S123_ApiKey.php and S123_InvoiceSettings.php fail to validate user permissions before executing sensitive database updates. An authenticated attacker with minimal privileges (Subscriber-level) can send crafted requests to overwrite the plugin's API key in the wp_options table or modify invoice settings. Furthermore, the vulnerability allows for the unauthorized modification of WooCommerce tax rate data within the wp_woocommerce_tax_rates table. The issue is present in all versions up to and including 1.7.0.

Affected products

  • saskaita123 Invoice123 (saskaita123-lt) <= 1.7.0

Timeline

  • 2026-07-10: disclosed: Initial publication of the CVE record

References