← WordPress Vulnerabilities
WordPress security by component

Invoice Generator

Invoice Generator is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: invoice-creator

CVE-2026-12415: Invoice Generator: Privilege escalation or authentication bypass

Invoice Generator is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.0.0.

PublishedJun 27, 2026
Known safe version> 1.0.0
Safe version
Jun 27, 2026 CVE-2026-12415
Invoice Generator: Privilege escalation or authentication bypass
Invoice Generator is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.0.0.
> 1.0.0
CVE9.8
NVDPending
Jun 24, 2026 CVE-2026-12416
Invoice Generator: Privilege escalation or authentication bypass
Invoice Generator is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.0.0.
> 1.0.0
CVE9.8
NVDPending