CVE-2026-12415
Last modified
CVE-2026-12415 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and user_email from POST data, and calls wp_update_user() without verifying authentication, ownership, or a nonce. This makes it possible for unauthenticated attackers to change the email address of any user, including administrators, and then trigger WordPress's password reset flow to gain access to the targeted account.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| pravel | Invoice Generator | <= 1.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-12415?
How severe is CVE-2026-12415?
How do I fix CVE-2026-12415?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12409The Landing Page Builder – Coming Soon page, Maintenance Mod…4.3
- CVE-2026-1241The Pelco, Inc. Sarix Professional 3 Series Cameras are vuln…8.7
- CVE-2026-12410Link following vulnerability in the Uninstaller component in…7.8
- CVE-2026-12411Broken Access Control in the devLXDInstancePatchHandler comp…9.6
- CVE-2026-12412Rejected reason: loading template...
- CVE-2026-12413An invalidly formatted IKEv2 fragment causes the Libreswan p…7.5
- CVE-2026-12416The Invoice Generator plugin for WordPress is vulnerable to …9.8
- CVE-2026-12417The SignUp & SignIn plugin for WordPress is vulnerable to Au…9.8
- CVE-2026-12418The User Frontend: AI Powered Frontend Posting, User Directo…5.3
- CVE-2026-12421The ARforms plugin for WordPress is vulnerable to Stored Cro…7.2
- CVE-2026-12425Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-12426The Members – Membership & User Role Editor Plugin plugin fo…5.3
Are you affected by CVE-2026-12415?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
