What is CVE-2026-27372?
CVE-2026-27372 is an unauthenticated sensitive data exposure vulnerability in the PeproDev Ultimate Invoice plugin versions up to 2.2.6. This flaw could allow attackers to access confidential information without any login credentials. Updating to the latest version of the plugin is strongly recommended.
Azərbaycanca: CVE-2026-27372 PeproDev Ultimate Invoice plugininin 2.2.6 və daha əvvəlki versiyalarında autentifikasiya olunmadan həssas məlumatların ifşası zəifliyidir. Bu boşluq zərərli şəxslərə heç bir giriş məlumatı olmadan sistemdəki məxfi məlumatlara çıxış imkanı verə bilər. Pluginin son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of the PeproDev Ultimate Invoice plugin are affected by CVE-2026-27372?
This vulnerability affects versions up to and including 2.2.6 of the PeproDev Ultimate Invoice plugin.
How can I protect against CVE-2026-27372?
To protect against this vulnerability, it is strongly recommended to update the PeproDev Ultimate Invoice plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.