CVE-2026-2343 PUBLISHED

PeproDev Ultimate Invoice <= 2.2.5 - Unauthenticated Invoice Archive Download

Assigner: WPScan
Reserved: 11.02.2026 Published: 25.03.2026 Updated: 25.03.2026

The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.

Product Status

Vendor Unknown
Product PeproDev Ultimate Invoice
Versions Default: unknown
  • affected from 0 to 2.2.5 (incl.)

Credits

  • Ashkan Moghaddas finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE