Impact
Unauthenticated Server Side Request Forgery (SSRF) in the PeproDev Ultimate Invoice plugin versions 2.2.6 and earlier allows an attacker to cause the WordPress site to send HTTP or HTTPS requests to arbitrary URLs. Based on typical SSRF exploitation scenarios, such outbound requests could expose internal resources or interact with external services, potentially leading to data leakage or further compromise.
Affected Systems
WordPress installations that include the PeproDev Ultimate Invoice plugin with a version of 2.2.6 or earlier are affected. The plugin is distributed by Pepro Dev under the product line PeproDev Ultimate Invoice. No other products or platforms are mentioned as impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low likelihood of observed exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because authentication is not required, any client able to interact with the vulnerable plugin endpoint can trigger the SSRF. In practice, an attacker would need to supply a specially crafted request to the plugin’s interface to initiate outbound calls, which is inferred from the unauthenticated nature of the flaw.
OpenCVE Enrichment