Impact
The vulnerability in PeproDev Ultimate Invoice allows unauthenticated users to access sensitive data that should be protected. This is a classic instance of data leakage, classified as CWE‑201, where the plugin fails to enforce proper access controls during data retrieval. The impact is a potential compromise of confidential financial information contained within invoices and related records, exposing sensitive business and personal data.
Affected Systems
The issue affects the PeproDev Ultimate Invoice WordPress plugin up to and including version 2.2.6. Host systems running WordPress with this plugin installed are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vendor has not listed this vulnerability in the CISA KEV catalog. Attackers could exploit the flaw by sending unauthenticated requests to the plugin’s data endpoints, which are likely reachable via the public web interface. Because the flaw does not appear to require authentication or privilege escalation, the risk surface is relatively high for any site displaying invoice data to the web.
OpenCVE Enrichment