Known vulnerabilities in PeproDev Ultimate Invoice
Advanced WooCommerce invoice plugin: create customizable HTML/PDF invoices, attach to emails, and let customers download styled invoices easily.
9Reported vulnerabilities
7.5Highest CVSS score
2.2.6Latest version
5,000+Active installs
What to do now
Update PeproDev Ultimate Invoice to 2.2.6 or later.
5 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-2343 | High | 0.2% | Before 2.2.6 | 2.2.6 |
March 27, 2026 |
| CVE-2024-25933 | High | 0.5% | 1.9.7 and earlier | 1.9.8 |
February 20, 2024 |
| CVE-2026-65510 | High | 0.3% | 2.2.6 and earlier | — | July 23, 2026 |
| CVE-2026-65516 | High | 0.3% | 2.2.6 and earlier | — | July 23, 2026 |
| CVE-2024-49298 | Medium | 0.3% | 2.0.6 and earlier | 2.0.7 |
October 15, 2024 |
| CVE-2026-65499 | Medium | 0.3% | 2.2.6 and earlier | — | July 23, 2026 |
| CVE-2026-27372 | Medium | 0.4% | 2.2.6 and earlier | — | July 23, 2026 |
| CVE-2024-13719 | Medium | 0.5% | 2.0.8 and earlier | 2.1.0 |
February 19, 2025 |
| CVE-2024-32518 | Medium | 0.4% | 2.0.0 and earlier | 2.0.2 |
April 15, 2024 |