Vulnerabilities / All in One Invite Codes
All in One Invite Codes vulnerabilities
Advisories WPSec published for All in One Invite Codes. Other sources may list more. Its attack surface: All in One Invite Codes on WPSec AttackSurface.
| Published | ID | Vulnerability | Severity | Fixed in |
|---|---|---|---|---|
| 2026-10-07 | WPSEC-2026-0593 | All in One Invite Codes <= 1.2.0 - Authenticated (Subscriber+) Missing Authorization to Sending Invites via Other Users' Invite Codes | Medium 5.4 | 1.3.0 |
| 2026-10-07 | WPSEC-2026-0592 | All in One Invite Codes <= 1.2.0 - Cross-Site Request Forgery to Invite Code Creation | Medium 4.3 | 1.3.0 |
| 2026-10-07 | WPSEC-2026-0591 | All in One Invite Codes <= 1.2.0 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Invite Code Disabling | Medium 4.3 | 1.3.0 |
License: CC BY 4.0