Junglewise Threat Intelligence

CVE-2026-87797: Sprout Invoices missing authorization in AJAX action

CVE-2026-87797 · Severity: medium · CVSS 4.3 · Published 2026-09-12

Executive brief

The Sprout Invoices WordPress plugin allows any logged-in subscriber to overwrite private notes on invoices and estimates belonging to other users. An attacker with a basic user account can modify sensitive internal notes, potentially disrupting business records and exposing confidential information that was intended to be visible only to specific staff members.

Technical details

The si_edit_private_note AJAX action in Sprout Invoices before 20.8.16 validates only a shared WordPress nonce but performs no capability or ownership checks before allowing private notes to be overwritten. An authenticated user (including subscribers) can craft a POST request to admin-ajax.php with an arbitrary record_id and note content, replacing the private note on any invoice or estimate record. The nonce is user-bound and emitted inline on published documents, making it accessible to any user viewing the page. The vulnerability is a broken access control flaw (CWE-862) that affects all authenticated users and has been patched in version 20.8.16.

Affected products

  • Sprout Apps Sprout Invoices before 20.8.16

Timeline

  • 2026-09-10: disclosed
  • 2026-09-12: patched: Fixed in version 20.8.16

References