Missing Authorization in Devs Accounting - Simple Accounting and Invoicing Solution Plugin for WordPress
CVE-2026-9175

5.3MEDIUM

What is CVE-2026-9175?

The Devs Accounting - Simple Accounting and Invoicing Solution plugin for WordPress contains a missing authorization vulnerability in its get_single_account() REST API callback. This issue arises because the permission callback is set to return true without any form of authentication or authorization checks, particularly affecting the /devs-accounting/v1/get-account/ endpoint. As a result, unauthenticated attackers can exploit this vulnerability to access sensitive financial account information, such as account names, bank details, and opening balances, simply by iterating through numeric account IDs, leading to potential breaches of private data security.

Affected Version(s)

Devs Accounting – Simple Accounting and Invoicing Solution 0 <= 1.2.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jamaal
.