SecAlerts
p

peprodev

Security Risk Profile

34
/100
low

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 25, 2023 to present

11
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
34/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
1
High
3
Medium
7
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
6

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
Infoleak
3

Most Affected Products

1. PeproDev Ultimate Profile Solutions4
2. PeproDev Ultimate Invoice2
3. PeproDev WooCommerce Receipt Uploader (WordPress plugin)1
4. Pepro Peprodev Ultimate Invoice Wordpress1
5. PeproDev PeproDev WooCommerce Receipt Uploader1

Recent Vulnerabilities

See more →
CVE-2026-4791
CVSS 6.4medium

PeproDev Ultimate Profile Solutions <= 8.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Attribute

Oct 10, 2026🔧 No Patch
CVE-2026-14314
CVSS 5.3medium

PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR

Aug 6, 2026🔧 No Patch
CVE-2026-2343
CVSS 5.3medium

PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download

Mar 25, 2026🔧 No Patch
CVE-2025-3921
CVSS 8.2EPSS 0%high

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req Function

May 7, 2025🔧 No Patch
CVE-2025-3844
CVSS 9.8EPSS 0%critical

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Authentication Bypass to Account Takeover

May 7, 2025🔧 No Patch
CVE-2025-3924
CVSS 5.3EPSS 0%medium

PeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Unauthenticated Email Enumeration

May 7, 2025🔧 No Patch
CVE-2024-13719
CVSS 5.3medium

PeproDev Ultimate Invoice <= 2.0.9 - Insecure Direct Object Reference to Unauthenticated Order Information Exposure

Feb 19, 2025🔧 No Patch
CVE-2024-8873
CVSS 6.1EPSS 0%medium

PeproDev WooCommerce Receipt Uploader <= 2.6.9 - Reflected Cross-Site Scripting

Nov 16, 2024🔧 No Patch
CVE-2024-32518
CVSS 5.3EPSS 0%medium

WordPress PeproDev Ultimate Invoice plugin <= 2.0.0 - Broken Access Control vulnerability

Apr 17, 2024🔧 No Patch
CVE-2024-25933
CVSS 7.5EPSS 0%high

WordPress PeproDev Ultimate Invoice plugin <= 1.9.7 - Sensitive Data Exposure vulnerability

Mar 17, 2024🔧 No Patch

Monitor peprodev in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.