Executive brief
PeproDev Ultimate Invoice is a WordPress plugin used for managing and generating invoices. A security flaw in versions 2.2.6 and earlier allows unauthorized individuals to access sensitive data that should be protected. This could lead to the exposure of private financial or customer information, potentially damaging a company's reputation or leading to further targeted attacks.
Technical details
The PeproDev Ultimate Invoice plugin for WordPress (versions <= 2.2.6) contains a sensitive data exposure vulnerability (CWE-201). The flaw allows an unauthenticated remote attacker to gain access to sensitive information. While the attack vector is network-based and requires no privileges, the CVSS vector indicates that some level of user interaction (such as a privileged user clicking a link) may be required for successful exploitation. At the time of the advisory, no official patch was available from the developer, though third-party mitigation rules have been released.
Affected products
- Pepro Dev. Group PeproDev Ultimate Invoice <= 2.2.6
Timeline
- 2025-11-23: disclosed: Reported by Derrick Gilliland
- 2026-07-23: advisory: Published by Patchstack and NVD