CVE-2024-25933: WordPress PeproDev Ultimate Invoice plugin <= 1.9.7 - Sensitive Data Exposure vulnerability
Published Mar 17, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7.
Affected Software
3 affected components
PeproDev Peprodev Ultimate Invoice Wordpress<1.9.8
Pepro Dev. Group Ultimate Invoice<=1.9.7
WordPress PeproDev Ultimate Invoice plugin<=1.9.7
Event History
Mar 17, 2024
CVE Published
via MITRE·04:04 PM
Data Sourced
via MITRE·04:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25933?
The severity of CVE-2024-25933 is classified as a high risk due to the exposure of sensitive information to unauthorized actors.
2
How do I fix CVE-2024-25933?
To fix CVE-2024-25933, update PeproDev Ultimate Invoice to version 1.9.8 or later.
3
What types of sensitive information are exposed in CVE-2024-25933?
CVE-2024-25933 can expose sensitive user data such as personal information and billing details.
4
Who is affected by CVE-2024-25933?
Users running PeproDev Ultimate Invoice versions up to 1.9.7 are affected by CVE-2024-25933.
5
What is the impact of CVE-2024-25933 on data security?
CVE-2024-25933 significantly impacts data security by allowing unauthorized access to sensitive information.