Impact
Unauthenticated Cross‑Site Scripting (XSS) in the PeproDev Ultimate Invoice WordPress plugin (versions 2.2.6 and earlier) allows an attacker to inject arbitrary scripts into the plugin’s output. This flaw arises when user input is rendered without proper validation, creating an input‑validation weakness identified as CWE‑79.
Affected Systems
The affected product is the PeproDev Ultimate Invoice WordPress plugin, versions up to and including 2.2.6. Any site running these versions is vulnerable, regardless of user privileges.
Risk and Exploitability
The CVSS score of 7.1 denotes a high‑severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the near term. The flaw is not listed in CISA’s KEV catalog, suggesting no confirmed public exploitation. Attackers can trigger the issue without authentication by submitting crafted input to the plugin’s exposed fields.
OpenCVE Enrichment