CVE-2026-2343: PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download
The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2343?
CVE-2026-2343 is considered a high severity vulnerability because it allows unauthenticated users to download sensitive invoice data.
How do I fix CVE-2026-2343?
To fix CVE-2026-2343, update the PeproDev Ultimate Invoice plugin to the latest version beyond 2.2.5.
What does CVE-2026-2343 affect?
CVE-2026-2343 affects the PeproDev Ultimate Invoice plugin for WordPress versions up to and including 2.2.5.
What type of vulnerability is CVE-2026-2343?
CVE-2026-2343 is an unauthenticated exposure vulnerability that allows unauthorized access to invoice archives.
Can CVE-2026-2343 lead to data breaches?
Yes, CVE-2026-2343 can potentially lead to data breaches by allowing attackers to download sensitive invoice information.