plugin

Sprout Invoices Vulnerabilities

23 known security issues reported for the Sprout Invoices WordPress plugin. Most recent disclosed Jul 8, 2026.

3 high 8 medium

Running Sprout Invoices on your site? Check whether your installed version is affected.

Scan your site free

Sprout Invoices – Client Invoicing & Estimates <= 20.8.13 - Missing Authorization

medium

The Sprout Invoices – Client Invoicing & Estimates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized a...

CVSS:
4.3
Affected:
up to 20.8.13
Fixed in:
20.8.14
Disclosed:
Jul 8, 2026

CVE-2026-57418 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.10 - Missing Authorization

medium

The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.10. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 20.8.10
Fixed in:
20.8.11
Disclosed:
Mar 19, 2026

CVE-2026-39562 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.9 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.

Affected:
up to 20.8.9
Fix:
No patched version reported
Disclosed:
Mar 13, 2026

CVE-2026-32401 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.9 - Authenticated (Author+) Local File Inclusion

high

The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 20.8.9. This makes it possible for authenticated attackers, with author-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP cod...

CVSS:
7.5
Affected:
up to 20.8.9
Fixed in:
20.8.10
Disclosed:
Feb 21, 2026

CVE-2026-32401 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.

Affected:
up to 20.8.8
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25364 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.8 - Missing Authorization

medium

The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.8. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 20.8.8
Fixed in:
20.8.9
Disclosed:
Feb 15, 2026

CVE-2026-25364 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.7 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

Affected:
up to 20.8.7
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64227 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] <= 20.8.7 (unfixed)

unknown

[en] Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

Affected:
up to 20.8.7
Fix:
No patched version reported
Disclosed:
Oct 29, 2025

CVE-2025-64229 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.7 - Missing Authorization

medium

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 20.8.7. This makes it possible for authenticated attackers, with Subscriber-level access and...

CVSS:
4.3
Affected:
up to 20.8.7
Fixed in:
20.8.8
Disclosed:
Oct 24, 2025

CVE-2025-64229 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.7 - Unauthenticated PHP Object Injection

high

The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 20.8.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a...

CVSS:
8.1
Affected:
up to 20.8.7
Fixed in:
20.8.8
Disclosed:
Sep 2, 2025

CVE-2025-64227 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.8.2

unknown

[en] Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.1.

Affected:
up to 20.8.2
Fixed in:
20.8.2
Disclosed:
Jan 27, 2025

CVE-2025-24606 on NVD →

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices <= 20.8.1 - Missing Authorization

medium

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the maybe_change_status() function in all versions up to, and including, 20.8.1. This makes it possible for authenticated attac...

CVSS:
5
Affected:
up to 20.8.1
Fixed in:
20.8.2
Disclosed:
Dec 22, 2024

CVE-2025-24606 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.8.1

unknown

[en] Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.0.

Affected:
up to 20.8.1
Fixed in:
20.8.1
Disclosed:
Dec 9, 2024

CVE-2024-53819 on NVD →

Client Invoicing by Sprout Invoices <= 20.8.0 - Insecure Direct Object Reference

medium

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 20.8.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to act on objec...

CVSS:
5.3
Affected:
up to 20.8.0
Fixed in:
20.8.1
Disclosed:
Dec 2, 2024

CVE-2024-53819 on NVD →

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4

unknown

Update the WordPress Client Invoicing by Sprout Invoices plugin to the latest available version (at least 20.5.4). Unknown discovered and reported this Sensitive Data Exposure vulnerability in WordPress Client Invoicing by Sprout Invoices Plugin. This vulnerability has been fixed in version 20.5.4.

Affected:
up to 20.5.4
Fixed in:
20.5.4
Disclosed:
Nov 14, 2023

Sprout Invoices <= 20.5.3 - Sensitive Information Exposure

medium

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to e...

CVSS:
4.3
Affected:
up to 20.5.4
Fixed in:
20.5.4
Disclosed:
Nov 13, 2023

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4

unknown

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to e...

Affected:
up to 20.5.4
Fixed in:
20.5.4
Disclosed:
Nov 13, 2023

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 19.9.7

unknown

[en] The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 19.9.7
Fixed in:
19.9.7
Disclosed:
Nov 17, 2021

CVE-2021-24787 on NVD →

Client Invoicing by Sprout Invoices <= 19.9.6 - Authenticated Stored Cross-Site Scripting

medium

The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to the plugin not sanitising and escaping some of its settings. This makes it possible for high privilege users to inject arbitrary web scripts in pages to perform attacks...

CVSS:
4.8
Affected:
up to 19.9.7
Fixed in:
19.9.7
Disclosed:
Oct 18, 2021

CVE-2021-24787 on NVD →

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress <= 9.3 - Missing Authorization

high

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 9.3. This is due to various missing capability & nonce checks on functions called via 'init' hooks. This makes it possible for unauthenticated...

CVSS:
7.3
Affected:
up to 9.3
Fixed in:
9.4
Disclosed:
Feb 9, 2016

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 9.4

unknown

The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 9.3. This is due to various missing capability & nonce checks on functions called via 'init' hooks. This makes it possible for unauthenticated...

Affected:
up to 9.4
Fixed in:
9.4
Disclosed:
Feb 9, 2016

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 20.5.4

unknown

The plugin is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to extract sensitive data including system configuration information.

Affected:
up to 20.5.4
Fixed in:
20.5.4

Client Invoicing by Sprout Invoices &#8211; Easy Estimates and Invoices for WordPress [sprout-invoices] < 19.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 19.1
Fixed in:
19.1

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database