Executive brief
Sprout Clients is a WordPress plugin used by businesses to manage client relationships and communications. A security flaw in versions 3.2.3 and earlier allows an unauthenticated attacker to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.
Technical details
The Sprout Clients plugin for WordPress (versions <= 3.2.3) contains an unauthenticated Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation (CWE-79). An attacker can exploit this by sending a crafted request to a vulnerable site, which requires a user (typically an administrator) to perform an action such as clicking a malicious link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue is resolved in version 3.2.4.
Affected products
- BoldGrid Sprout Clients <= 3.2.3
Timeline
- 2026-06-08: other: Vulnerability reported by researcher dutafi
- 2026-07-16: advisory: Initial advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD dataset
- 2026-07-23: patched: Patch confirmed available in version 3.2.4