LiveActive security incident?Get immediate response
CVE Record

CVE-2024-32518: WordPress PeproDev Ultimate Invoice plugin <= 2.0.0 - Broken Access Control vulnerability

Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 2.0.0.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

PeproDev Ultimate Invoice for WordPress lacks an authorization check in versions through 2.0.0. A remote, unauthenticated person may be able to make unauthorized changes. The supplied scoring indicates no expected confidentiality or availability impact, but invoice-related integrity could be affected.

Executive priority

Treat this as a scheduled but prompt remediation item for exposed sites, escalating if the plugin handles business-critical invoice data or suspicious changes appear. The moderate score reflects limited stated impact, not proof that affected deployments are harmless.

Technical view

CVE-2024-32518 is a CWE-862 missing-authorization vulnerability reachable over the network with low complexity, no privileges, and no user interaction. CVSS 3.1 is 5.3: integrity impact is low, while confidentiality and availability impacts are scored none. The affected operation is not identified in the bundle.

Likely exposure

Internet-accessible WordPress sites running PeproDev Ultimate Invoice through version 2.0.0 are the likely exposure. Actual risk depends on whether the vulnerable functionality is enabled and reachable. The supplied records provide no affected endpoint, configuration prerequisites, or reliable installation prevalence.

Exploitation context

The supplied record does not mark this CVE as KEV, and the bundle provides no evidence of active exploitation or a public proof of concept. Its unauthenticated, network-accessible characteristics make opportunistic abuse plausible, but observed exploitation cannot be claimed from these sources.

Researcher notes

Public details are sparse. The record establishes missing authorization through 2.0.0 and an unauthenticated network integrity impact, but does not identify the vulnerable action, endpoint, fixed version, prerequisites, or exploitation evidence. Avoid assuming broader data access or system compromise without additional vendor evidence.

Mitigation direction

  • Inventory WordPress sites and identify PeproDev Ultimate Invoice installations at version 2.0.0 or earlier.
  • Check current vendor or Patchstack guidance for a corrected release or documented mitigation.
  • Apply a vendor-supported update after testing when one is confirmed available.
  • Disable the plugin if unnecessary or if no supported correction is available.
  • Restrict public access to affected functionality where operationally feasible.

Validation and detection

  • Confirm the installed plugin version on every WordPress instance.
  • Verify unauthenticated requests cannot perform invoice-related changes using an authorized staging test.
  • Review application and web logs for unexplained unauthenticated requests or data changes.
  • Confirm any vendor-supported update or compensating control remains active after deployment.
  • Review affected records for unauthorized modifications and follow incident procedures if found.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-862: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2024-32518 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N3.91.4Patchstack

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2024-32518Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Pepro Dev. GroupPeproDev Ultimate Invoicepepro-ultimate-invoice, n/aunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-862 · source CWE mapping

Missing Authorization

Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.