CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14313

Mitre link : CVE-2026-14313

CVE.ORG link : CVE-2026-14313


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-639

Authorization Bypass Through User-Controlled Key