Unauthenticated SSRF Vulnerability in PeproDev Ultimate Invoice Plugin by WordPress
CVE-2026-65516

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65516?

An unauthenticated Server Side Request Forgery (SSRF) vulnerability exists in versions of the PeproDev Ultimate Invoice plugin up to 2.2.6. This security flaw allows attackers to manipulate the server into making unauthorized requests to internal or external systems, potentially leading to further exploitation or data exposure.

Affected Version(s)

PeproDev Ultimate Invoice <= 2.2.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

longnv719 | Patchstack Bug Bounty Program
.