CVE-2026-14313
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 6, 2026 · Last modified: Aug 6, 2026 · CWE-352 · CWE-639
Not enough EPSS history yet.
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated missing-authorization / IDOR write. Requires WooCommerce.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-182756.5 MED—
———Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied to a many=True related field whose queryset restriction was applied to the ManyRelatedField instead of its child_relation and therefore had no effect7hCVE-2026-182588.8 HIG—
———Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request body, which are queried against the global model manager instead of the request-scoped queryset7hCVE-2026-666924.3 MED—
———Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.8hCVE-2026-666866.5 MED—
———Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.8hCVE-2026-666814.3 MED—
———Unauthenticated Cross Site Request Forgery (CSRF) in Theme My Login <= 7.1.14 versions.7hCVE-2026-655237.5 HIG—
———Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0.1 versions.8h