Junglewise Threat Intelligence

CVE-2026-65499: PeproDev Ultimate Invoice broken access control

CVE-2026-65499 · Severity: medium · CVSS 6.5 · Published 2026-07-23

Technologies: Pepro Dev. Group Ultimate Invoice. Vendors: Pepro Dev. Group.

Executive brief

PeproDev Ultimate Invoice is a WordPress plugin used for managing and generating invoices. A security flaw in versions 2.2.6 and earlier allows unauthorized individuals to perform actions or access data that should be restricted to administrators. This could lead to the exposure of sensitive billing information or unauthorized changes to invoice records.

Technical details

The PeproDev Ultimate Invoice plugin for WordPress (versions <= 2.2.6) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or access resources that should require higher privileges. The vulnerability stems from a lack of proper validation of user permissions or nonce tokens. Successful exploitation could allow an attacker to view or modify invoice-related data. As of the advisory date, no official patch has been released.

Affected products

  • Pepro Dev. Group PeproDev Ultimate Invoice <= 2.2.6

Timeline

  • 2026-03-02: disclosed: Reported by babyhack(@OPCIA) via Patchstack
  • 2026-07-23: advisory: NVD and Patchstack published the advisory

References

Related threats