VYPR

Invoice Generator

by WordPress

CVEs (2)

  • CVE-2026-12416CriJun 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no…

  • CVE-2026-12415CriJun 27, 2026
    risk 0.00cvss 9.8epss 0.01

    The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account,…