
SecAlerts@SecAlertsCo
Disclosure
🧾 WordPress Easy Invoice plugin has an unauthenticated RCE flaw (CVSS 10). No login needed to execute code. If you're running <= 2.1.19, update immediately. CVE-2026-48836 https://secalerts.co/vulnerability/CVE-2026-48836 https://t.co/89jmW0w03k
Post summary
WordPress Easy Invoice plugin versions <=2.1.19 contain an unauthenticated remote code execution vulnerability (CVSS 10); users should update immediately.
0000057
836 followersView on X
