CVSS
5.3
CVSS v3.1
EPSS
0.1%
Exploit Prediction Score
Published
August 6, 2026
Exploitability
EPSS probability 0.1%
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).