The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Peprodev Ultimate Invoice
Peprodev Ultimate Invoice peprodev Ultimate Invoice Wordpress Wordpress wordpress |
|
| Vendors & Products |
Peprodev Ultimate Invoice
Peprodev Ultimate Invoice peprodev Ultimate Invoice Wordpress Wordpress wordpress |
Wed, 25 Mar 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII. | |
| Title | PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-25T06:00:02.327Z
Reserved: 2026-02-11T14:13:06.230Z
Link: CVE-2026-2343
No data.
Status : Received
Published: 2026-03-25T06:16:28.407
Modified: 2026-03-25T06:16:28.407
Link: CVE-2026-2343
No data.
OpenCVE Enrichment
Updated: 2026-03-25T11:35:39Z
Weaknesses
No weakness.