Junglewise Threat Intelligence

CVE-2026-27372: Pepro Dev. Group PeproDev Ultimate Invoice sensitive data exposure

CVE-2026-27372 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: Pepro Dev. Group Ultimate Invoice. Vendors: Pepro Dev. Group.

Executive brief

PeproDev Ultimate Invoice is a WordPress plugin used for managing and generating invoices. A security flaw in versions 2.2.6 and earlier allows unauthorized individuals to access sensitive data that should be protected. This could lead to the exposure of private financial or customer information, potentially damaging a company's reputation or leading to further targeted attacks.

Technical details

The PeproDev Ultimate Invoice plugin for WordPress (versions <= 2.2.6) contains a sensitive data exposure vulnerability (CWE-201). The flaw allows an unauthenticated remote attacker to gain access to sensitive information. While the attack vector is network-based and requires no privileges, the CVSS vector indicates that some level of user interaction (such as a privileged user clicking a link) may be required for successful exploitation. At the time of the advisory, no official patch was available from the developer, though third-party mitigation rules have been released.

Affected products

  • Pepro Dev. Group PeproDev Ultimate Invoice <= 2.2.6

Timeline

  • 2025-11-23: disclosed: Reported by Derrick Gilliland
  • 2026-07-23: advisory: Published by Patchstack and NVD

References

Related threats