PT-2026-53043 · WordPress · Invoice Generator

·

CVE-2026-12415

·

Published

2026-06-27

·

Updated

2026-07-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Invoice Generator versions prior to 1.0.1
Description The Invoice Generator plugin for WordPress allows privilege escalation because it fails to perform a capability check on the pravel invoice edit account() AJAX action. The handler is exposed via the wp ajax nopriv pravel invoice edit account endpoint and accepts the user id and user email variables from POST data. Because the plugin calls wp update user() without verifying authentication, ownership, or a nonce, unauthenticated attackers can change the email address of any user, including administrators. This allows them to trigger the password reset flow and gain unauthorized access to the targeted account.
Recommendations Update the plugin to a version newer than 1.0.0.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12415

Affected Products

Invoice Generator