Description
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross‑Site Scripting (XSS) in the PeproDev Ultimate Invoice WordPress plugin (versions 2.2.6 and earlier) allows an attacker to inject arbitrary scripts into the plugin’s output. This flaw arises when user input is rendered without proper validation, creating an input‑validation weakness identified as CWE‑79.

Affected Systems

The affected product is the PeproDev Ultimate Invoice WordPress plugin, versions up to and including 2.2.6. Any site running these versions is vulnerable, regardless of user privileges.

Risk and Exploitability

The CVSS score of 7.1 denotes a high‑severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the near term. The flaw is not listed in CISA’s KEV catalog, suggesting no confirmed public exploitation. Attackers can trigger the issue without authentication by submitting crafted input to the plugin’s exposed fields.

Generated by OpenCVE AI on August 4, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PeproDev Ultimate Invoice to the latest release that fixes the XSS flaw.
  • If an upgrade cannot be performed immediately, temporarily deactivate or delete the plugin to prevent exploitation.
  • Add a Content Security Policy header that blocks inline scripts on pages served by the plugin to limit potential impact.

Generated by OpenCVE AI on August 4, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Peprodev
Peprodev peprodev Ultimate Invoice
Wordpress
Wordpress wordpress
Vendors & Products Peprodev
Peprodev peprodev Ultimate Invoice
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Title WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Peprodev Peprodev Ultimate Invoice
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:50:44.301Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65510

cve-icon Vulnrichment

Updated: 2026-07-23T13:54:26.328Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:44.010

Modified: 2026-07-23T15:18:09.497

Link: CVE-2026-65510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')