Sprout Invoices – Client Invoicing & Estimates <= 20.8.13 - Missing Authorization
medium
The Sprout Invoices – Client Invoicing & Estimates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized a...
- CVSS:
- 4.3
- Affected:
- up to 20.8.13
- Fixed in:
- 20.8.14
- Disclosed:
- Jul 8, 2026
CVE-2026-57418 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.10 - Missing Authorization
medium
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 20.8.10
- Fixed in:
- 20.8.11
- Disclosed:
- Mar 19, 2026
CVE-2026-39562 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.9 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.
- Affected:
- up to 20.8.9
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2026
CVE-2026-32401 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.9 - Authenticated (Author+) Local File Inclusion
high
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 20.8.9. This makes it possible for authenticated attackers, with author-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP cod...
- CVSS:
- 7.5
- Affected:
- up to 20.8.9
- Fixed in:
- 20.8.10
- Disclosed:
- Feb 21, 2026
CVE-2026-32401 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.
- Affected:
- up to 20.8.8
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25364 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.8 - Missing Authorization
medium
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 20.8.8
- Fixed in:
- 20.8.9
- Disclosed:
- Feb 15, 2026
CVE-2026-25364 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.7 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
- Affected:
- up to 20.8.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-64227 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
- Affected:
- up to 20.8.7
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2025
CVE-2025-64229 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.7 - Missing Authorization
medium
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 20.8.7. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 4.3
- Affected:
- up to 20.8.7
- Fixed in:
- 20.8.8
- Disclosed:
- Oct 24, 2025
CVE-2025-64229 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.7 - Unauthenticated PHP Object Injection
high
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 20.8.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a...
- CVSS:
- 8.1
- Affected:
- up to 20.8.7
- Fixed in:
- 20.8.8
- Disclosed:
- Sep 2, 2025
CVE-2025-64227 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.8.2
unknown
[en] Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.1.
- Affected:
- up to 20.8.2
- Fixed in:
- 20.8.2
- Disclosed:
- Jan 27, 2025
CVE-2025-24606 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices <= 20.8.1 - Missing Authorization
medium
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the maybe_change_status() function in all versions up to, and including, 20.8.1. This makes it possible for authenticated attac...
- CVSS:
- 5
- Affected:
- up to 20.8.1
- Fixed in:
- 20.8.2
- Disclosed:
- Dec 22, 2024
CVE-2025-24606 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.8.1
unknown
[en] Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.0.
- Affected:
- up to 20.8.1
- Fixed in:
- 20.8.1
- Disclosed:
- Dec 9, 2024
CVE-2024-53819 on NVD →
Client Invoicing by Sprout Invoices <= 20.8.0 - Insecure Direct Object Reference
medium
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 20.8.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to act on objec...
- CVSS:
- 5.3
- Affected:
- up to 20.8.0
- Fixed in:
- 20.8.1
- Disclosed:
- Dec 2, 2024
CVE-2024-53819 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4
unknown
Update the WordPress Client Invoicing by Sprout Invoices plugin to the latest available version (at least 20.5.4).
Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress Client Invoicing by Sprout Invoices Plugin. This vulnerability has been fixed in version 20.5.4.
- Affected:
- up to 20.5.4
- Fixed in:
- 20.5.4
- Disclosed:
- Nov 14, 2023
Sprout Invoices <= 20.5.3 - Sensitive Information Exposure
medium
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to e...
- CVSS:
- 4.3
- Affected:
- up to 20.5.4
- Fixed in:
- 20.5.4
- Disclosed:
- Nov 13, 2023
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4
unknown
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to e...
- Affected:
- up to 20.5.4
- Fixed in:
- 20.5.4
- Disclosed:
- Nov 13, 2023
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 19.9.7
unknown
[en] The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 19.9.7
- Fixed in:
- 19.9.7
- Disclosed:
- Nov 17, 2021
CVE-2021-24787 on NVD →
Client Invoicing by Sprout Invoices <= 19.9.6 - Authenticated Stored Cross-Site Scripting
medium
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to the plugin not sanitising and escaping some of its settings. This makes it possible for high privilege users to inject arbitrary web scripts in pages to perform attacks...
- CVSS:
- 4.8
- Affected:
- up to 19.9.7
- Fixed in:
- 19.9.7
- Disclosed:
- Oct 18, 2021
CVE-2021-24787 on NVD →
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress <= 9.3 - Missing Authorization
high
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 9.3. This is due to various missing capability & nonce checks on functions called via 'init' hooks. This makes it possible for unauthenticated...
- CVSS:
- 7.3
- Affected:
- up to 9.3
- Fixed in:
- 9.4
- Disclosed:
- Feb 9, 2016
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 9.4
unknown
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 9.3. This is due to various missing capability & nonce checks on functions called via 'init' hooks. This makes it possible for unauthenticated...
- Affected:
- up to 9.4
- Fixed in:
- 9.4
- Disclosed:
- Feb 9, 2016
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4
unknown
The plugin is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to extract sensitive data including system configuration information.
- Affected:
- up to 20.5.4
- Fixed in:
- 20.5.4
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress [sprout-invoices] < 19.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 19.1
- Fixed in:
- 19.1
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database