Executive brief
PeproDev Ultimate Invoice is a WordPress plugin used for managing and generating invoices. A security flaw in versions 2.2.6 and earlier allows unauthorized individuals to perform actions or access data that should be restricted to administrators. This could lead to the exposure of sensitive billing information or unauthorized changes to invoice records.
Technical details
The PeproDev Ultimate Invoice plugin for WordPress (versions <= 2.2.6) contains a broken access control vulnerability due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or access resources that should require higher privileges. The vulnerability stems from a lack of proper validation of user permissions or nonce tokens. Successful exploitation could allow an attacker to view or modify invoice-related data. As of the advisory date, no official patch has been released.
Affected products
- Pepro Dev. Group PeproDev Ultimate Invoice <= 2.2.6
Timeline
- 2026-03-02: disclosed: Reported by babyhack(@OPCIA) via Patchstack
- 2026-07-23: advisory: NVD and Patchstack published the advisory