PT-2026-53043 · Undefined · Undefined
Published
2026-06-27
·
Updated
2026-06-27
·
CVE-2026-12415
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel invoice edit account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp ajax nopriv pravel invoice edit account, accepts an attacker-controlled user id and user email from POST data, and calls wp update user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attackers to change the email address of any user, including administrators, and then trigger WordPress's password reset flow to gain access to the targeted account.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined