Executive brief
Easy Invoice is a WordPress plugin for managing invoices in online stores and service businesses. This vulnerability allows unauthenticated attackers to access pages or perform actions they should not be permitted to, potentially viewing other users' invoice data, payment information, or customer records.
Technical details
The vulnerability is a broken access control flaw in Easy Invoice plugin versions up to 2.3.8 that fails to properly enforce authentication checks on sensitive operations. An unauthenticated attacker can exploit this by making direct requests to protected endpoints without valid credentials, bypassing authorization controls and gaining unauthorized access to invoice data and related functionality. The vulnerability requires no authentication or user interaction and is remotely exploitable. A fix is available in version 2.4.0 or later.
Affected products
- MantraBrain Easy Invoice up to 2.3.8
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Version 2.4.0 released