← Back

CVE-2024-13719

nvd nist
Published: Feb 19, 2025Modified: Apr 8, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which can contain PII of users.

Affected (1)

1 product
Peprodev Ultimate Invoice
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0.8

Timeline

No history available yet.