CVE-2025-64227: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64227?
CVE-2025-64227 is classified as a critical vulnerability due to its potential for object injection and deserialization of untrusted data.
How do I fix CVE-2025-64227?
To mitigate CVE-2025-64227, update your Sprout Invoices Client Invoicing to version 20.8.8 or later.
Which versions are affected by CVE-2025-64227?
CVE-2025-64227 affects all versions of Sprout Invoices Client Invoicing from n/a up to and including 20.8.7.
What kind of attacks can CVE-2025-64227 allow?
CVE-2025-64227 can allow attackers to exploit the deserialization of untrusted data, leading to potential remote code execution.
Is CVE-2025-64227 specific to a certain platform?
Yes, CVE-2025-64227 is specific to the BoldGrid Client Invoicing by Sprout Invoices plugin for WordPress.