First published: Wed Feb 19 2025(Updated: )
The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Peprodev Ultimate Invoice | <=2.0.8 | |
Ultimate Invoice | <=2.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13719 is considered a high-severity vulnerability due to the potential for unauthenticated attackers to exploit it.
To fix CVE-2024-13719, update the PeproDev Ultimate Invoice plugin to version 2.0.9 or later.
All users of the PeproDev Ultimate Invoice plugin for WordPress up to and including version 2.0.8 are affected by CVE-2024-13719.
CVE-2024-13719 is categorized as an Insecure Direct Object Reference vulnerability.
Yes, CVE-2024-13719 can lead to unauthorized data exposure by allowing attackers to view sensitive invoices.