Impact
A flaw in the PeproDev Ultimate Invoice plugin for WordPress allows unauthenticated users to bypass an otherwise required access control check on the plugin’s endpoints. Because the check is missing, an attacker could gain access to invoice information that is normally protected, exposing sensitive financial data to anyone able to reach the site. The vulnerability is identified as a classic Broken Access Control weakness (CWE-862).
Affected Systems
All installations of Pepro Dev’s PeproDev Ultimate Invoice plugin at version 2.2.6 or earlier on any WordPress site are affected. No other specific WordPress core or plugin versions are mentioned as necessary conditions.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% points to a low but non-zero probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can likely exploit the issue by delivering unauthenticated HTTP requests to the plugin’s exposed endpoints, thus bypassing the intended authorization checks and lifting the protection on invoice data.
OpenCVE Enrichment