Executive brief
A security flaw exists in the Sprout Invoices plugin for WordPress, which is used by businesses to manage client billing and invoicing. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to bypass security checks and access sensitive information they should not be able to see. This could lead to the exposure of private financial data or client details, potentially impacting business operations and data privacy compliance.
Technical details
A missing authorization vulnerability (CWE-862) exists in the BoldGrid Client Invoicing by Sprout Invoices plugin for WordPress. The flaw is rooted in incorrectly configured access control security levels within the plugin's functions. An attacker authenticated with low-level privileges (such as a Subscriber) can exploit this lack of proper authorization checks to perform actions or access data intended for higher-privileged users. The vulnerability is reachable over the network without user interaction. A fix is available in version 20.8.14, which implements the necessary authorization checks.
Affected products
- BoldGrid Client Invoicing by Sprout Invoices <= 20.8.13
Timeline
- 2026-05-25: other: Vulnerability reported by researcher she11f
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: disclosed: CVE published to NVD dataset
- 2026-07-13: patched: Patch confirmed available in version 20.8.14