Skip to content
Vulnerability intelligence

CVE-2026-12416

CVE-2026-12415: wp_ajax_nopriv_pravel_invoice_edit_account requires no capability check. Any unauthenticated request escalates to administrator. Plugin Roulette claims another round.

WordPress 2026