The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
mitre·CWE-668·Published 2019-09-20