WordPress Vulnerability Scanner WPSec
  • Features
  • Pricing
  • Blog
  • Log In
  • Sign Up
Vulnerabilities / All in One Invite Codes

All in One Invite Codes vulnerabilities

Advisories WPSec published for All in One Invite Codes. Other sources may list more. Its attack surface: All in One Invite Codes on WPSec AttackSurface.

PublishedIDVulnerabilitySeverityFixed in
2026-10-07 WPSEC-2026-0593 All in One Invite Codes <= 1.2.0 - Authenticated (Subscriber+) Missing Authorization to Sending Invites via Other Users' Invite Codes Medium 5.4 1.3.0
2026-10-07 WPSEC-2026-0592 All in One Invite Codes <= 1.2.0 - Cross-Site Request Forgery to Invite Code Creation Medium 4.3 1.3.0
2026-10-07 WPSEC-2026-0591 All in One Invite Codes <= 1.2.0 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Invite Code Disabling Medium 4.3 1.3.0

License: CC BY 4.0

footer-logo

WPSec.com is an online security scanner for WordPress vulnerabilities. We keep track of all your WordPress installations and tell you as soon as they are outdated.

  • Explore

    Features Pricing Vulnerabilities Sign up
  • Others

    Terms and conditions Privacy GDPR Blog Contact

WPSec is a service by Triop AB, Funäsdalen Sweden | Advisories licensed under CC BY 4.0