Missing Authorization in Devs Accounting - Simple Accounting and Invoicing Solution Plugin for WordPress
CVE-2026-9175
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 June 2026
What is CVE-2026-9175?
The Devs Accounting - Simple Accounting and Invoicing Solution plugin for WordPress contains a missing authorization vulnerability in its get_single_account() REST API callback. This issue arises because the permission callback is set to return true without any form of authentication or authorization checks, particularly affecting the /devs-accounting/v1/get-account/ endpoint. As a result, unauthenticated attackers can exploit this vulnerability to access sensitive financial account information, such as account names, bank details, and opening balances, simply by iterating through numeric account IDs, leading to potential breaches of private data security.
Affected Version(s)
Devs Accounting β Simple Accounting and Invoicing Solution 0 <= 1.2.0