CVE-2026-66676: WordPress Easy Invoice plugin <= 2.3.8 - Broken Access Control vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Affected Software
1 affected component
WordPress Easy Invoice<=2.3.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Invoice pluginto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges. The network attack vector indicates it can be targeted remotely.
2
Which installations are affected?
WordPress sites using the Easy Invoice plugin at version 2.3.8 or earlier are affected according to the available information.
3
What is the expected security impact?
The reported impact is limited confidentiality loss. No integrity or availability impact is indicated.