VYPR

Invoice Creator

by WordPress

CVEs (1)

  • CVE-2026-12416Jun 24, 2026
    risk 0.00cvss epss

    The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no…