Junglewise Threat Intelligence

CVE-2026-65516: Pepro Dev. Group PeproDev Ultimate Invoice SSRF

CVE-2026-65516 · Severity: high · CVSS 7.2 · Published 2026-07-23

Technologies: Pepro Dev. Group Ultimate Invoice. Vendors: Pepro Dev. Group.

Executive brief

PeproDev Ultimate Invoice is a WordPress plugin used for managing and generating customer invoices. A security flaw in versions 2.2.6 and earlier allows unauthenticated attackers to force the website to make unauthorized requests to internal or external servers. This can lead to the exposure of sensitive internal data or be used to bypass security controls to reach other systems on the network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the PeproDev Ultimate Invoice plugin for WordPress (versions <= 2.2.6). The flaw allows an unauthenticated remote attacker to submit a crafted request that causes the server to initiate outbound network connections to arbitrary destinations. This can be leveraged to scan internal networks, access metadata services in cloud environments, or interact with other internal services that are not directly accessible from the internet. As of the advisory date, no official patch has been released by the developer.

Affected products

  • Pepro Dev. Group PeproDev Ultimate Invoice <= 2.2.6

Timeline

  • 2026-05-22: other: Reported by researcher longnv719
  • 2026-07-23: disclosed: Vulnerability published by Patchstack and NVD

References

Related threats