CVE-2026-2343
EUVD-2026-1518825.03.2026, 06:16
The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP archives containing exported invoice PDFs. The ZIP files are named predictably making it possible to brute force and retreive PII.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.