Executive brief
A security flaw exists in the Sprout Invoices plugin for WordPress, which is used by businesses to manage client billing and invoicing. Due to a failure in verifying user permissions, an unauthorized person could potentially bypass security controls to perform actions they should not be allowed to. This could lead to unauthorized changes in the invoicing system, though it does not directly expose sensitive data or crash the site.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the BoldGrid Client Invoicing by Sprout Invoices plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels, allowing unauthenticated attackers to execute functions that should be restricted to higher-privileged users. The attack can be carried out over the network without any user interaction. While the technical impact is categorized as partial integrity loss, it allows for the exploitation of administrative or restricted functions. The issue is resolved in version 20.8.11.
Affected products
- BoldGrid Client Invoicing by Sprout Invoices <= 20.8.10
Timeline
- 2026-02-17: other: Vulnerability reported by researcher
- 2026-03-19: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published
- 2026-03-19: patched: Version 20.8.11 released to address the issue