The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 19 Feb 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users. | |
Title | PeproDev Ultimate Invoice <= 2.0.8 - Insecure Direct Object Reference to Unauthenticated Order Information Exposure | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-19T07:32:07.577Z
Updated: 2025-02-19T21:33:25.744Z
Reserved: 2025-01-24T15:41:02.104Z
Link: CVE-2024-13719

Updated: 2025-02-19T21:21:49.528Z

Status : Received
Published: 2025-02-19T08:15:20.737
Modified: 2025-02-19T08:15:20.737
Link: CVE-2024-13719

No data.