B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-12415 - Invoice Generator <= 1.0.0 - Unauthenticated Privilege Escalation via Account Takeover via 'user_id' Parameter

CVE ID :CVE-2026-12415 Published : June 27, 2026, 4:30 a.m. | 4 hours, 41 minutes ago Description :The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and...

Original-Artikel öffnen Zurück zur Übersicht