PT-2026-63930 · Peprodev+1 · Peprodev Ultimate Invoice

CVE-2026-65516

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PeproDev Ultimate Invoice versions prior to 2.2.7
Description An unauthenticated Server Side Request Forgery (SSRF) exists in the PeproDev Ultimate Invoice plugin for WordPress. This flaw allows attackers to initiate web requests to arbitrary locations from the web application, which can be leveraged to query or modify information within internal services. SSRF is a flaw where a server is tricked into making requests to an unintended location.
Recommendations Update to a version newer than 2.2.6.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65516

Affected Products

Peprodev Ultimate Invoice