Unauthenticated Remote Code Execution in Easy Invoice Plugin by WordPress
CVE-2026-48836
10CRITICAL
What is CVE-2026-48836?
The Easy Invoice plugin for WordPress versions 2.1.19 and earlier is susceptible to an unauthenticated remote code execution vulnerability. This flaw could allow attackers to execute arbitrary code on the server, potentially leading to significant data breaches or unauthorized administrative access. It is crucial for users of this plugin to apply the latest security patches and keep their installations updated to mitigate these risks.
Affected Version(s)
Easy Invoice <= 2.1.19