Junglewise Threat Intelligence

CVE-2026-48836: MantraBrain Easy Invoice unauthenticated RCE in WordPress plugin

CVE-2026-48836 · Severity: critical · CVSS 10 · Published 2026-06-15

Executive brief

Easy Invoice is a WordPress plugin used for managing and generating invoices. A critical security flaw allows unauthorized attackers to remotely execute malicious code on the website's server without needing a password. This could lead to a total takeover of the website, theft of customer data, or the installation of backdoors for persistent access.

Technical details

The Easy Invoice plugin for WordPress (up to version 2.1.19) is vulnerable to unauthenticated Remote Code Execution (RCE) due to improper control of code generation (CWE-94). The vulnerability allows a remote attacker to inject and execute arbitrary PHP code on the server without any prior authentication or user interaction. This is classified as a high-priority injection flaw (OWASP A3) that can lead to full system compromise. The issue is resolved in version 2.1.20.

Affected products

  • MantraBrain Easy Invoice <= 2.1.19

Timeline

  • 2026-04-28: other: Reported by researcher HaiND
  • 2026-06-01: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-06-01: patched: Patch released in version 2.1.20

References

Related threats