Unauthenticated Access Control Issue in Easy Invoice Plugin by WordPress
CVE-2026-66676
5.3MEDIUM
What is CVE-2026-66676?
The Easy Invoice plugin for WordPress, specifically versions up to 2.3.8, contains an unauthenticated broken access control vulnerability. This flaw allows unauthorized users to exploit the system, potentially leading to unauthorized actions within the application. It is essential for users of this plugin to review security updates and implement necessary patches to safeguard their systems against this vulnerability.
Affected Version(s)
Easy Invoice <= 2.3.8