Unauthenticated Access Control Flaw in PeproDev Ultimate Invoice Plugin by PeproDev
CVE-2026-65499
6.5MEDIUM
What is CVE-2026-65499?
The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to an unauthenticated broken access control issue. This vulnerability allows attackers to access sensitive functionalities without proper authentication, posing a risk to the integrity of user data and operations. Versions 2.2.6 and below are impacted, making it crucial for users to upgrade to patched versions to mitigate potential security threats.
Affected Version(s)
PeproDev Ultimate Invoice <= 2.2.6