Description
Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in PeproDev Ultimate Invoice allows unauthenticated users to access sensitive data that should be protected. This is a classic instance of data leakage, classified as CWE‑201, where the plugin fails to enforce proper access controls during data retrieval. The impact is a potential compromise of confidential financial information contained within invoices and related records, exposing sensitive business and personal data.

Affected Systems

The issue affects the PeproDev Ultimate Invoice WordPress plugin up to and including version 2.2.6. Host systems running WordPress with this plugin installed are susceptible.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate level of severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vendor has not listed this vulnerability in the CISA KEV catalog. Attackers could exploit the flaw by sending unauthenticated requests to the plugin’s data endpoints, which are likely reachable via the public web interface. Because the flaw does not appear to require authentication or privilege escalation, the risk surface is relatively high for any site displaying invoice data to the web.

Generated by OpenCVE AI on August 3, 2026 at 22:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update PeproDev Ultimate Invoice to version 2.2.7 or later, which contains the fix for the sensitive data exposure flaw.
  • If an immediate upgrade is not feasible, disable the plugin or restrict access to its pages to authenticated administrators only.
  • Review and remove any publicly exposed invoice URLs or endpoints, ensuring that only authorized users can retrieve invoice data.

Generated by OpenCVE AI on August 3, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Peprodev
Peprodev peprodev Ultimate Invoice
Wordpress
Wordpress wordpress
Vendors & Products Peprodev
Peprodev peprodev Ultimate Invoice
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.
Title WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Peprodev Peprodev Ultimate Invoice
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T16:03:06.902Z

Reserved: 2026-02-19T09:51:54.220Z

Link: CVE-2026-27372

cve-icon Vulnrichment

Updated: 2026-07-23T16:02:39.398Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:17.890

Modified: 2026-07-23T16:17:16.953

Link: CVE-2026-27372

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data