AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14313

MEDIUM · CVSS 5.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The PeproDev WooCommerce Receipt Uploader plugin for WordPress, up to version 2.8.0, is susceptible to an unauthenticated missing authorization vulnerability that allows for IDOR write operations. This could enable attackers to manipulate or upload receipts without proper permissions, potentially compromising user data and system integrity. WordPress site administrators using this plugin, especially those with WooCommerce enabled, should prioritize addressing this vulnerability to safeguard their platforms.

CVE
CVE-2026-14313
Severity
MEDIUM
CVSS
5.3
EPSS
0.12%
WordPress

Original NVD Description

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.