Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-12415: WordPress Invoice Generator Plugin Allows Email Hijacking

CVE-2026-12415
Summary

The WordPress Invoice Generator plugin has a security flaw that lets attackers change the email address of any user, including administrators. This can be used to gain access to sensitive accounts. Update the plugin to the latest version to fix this issue.

Original title
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including,...
Original description
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attackers to change the email address of any user, including administrators, and then trigger WordPress's password reset flow to gain access to the targeted account.
nvd CVSS3.1 9.8
Vulnerability type
CWE-269 Improper Privilege Management
Published: 27 Jun 2026 · Updated: 23 Jul 2026 · First seen: 27 Jun 2026