CVE-2025-64229: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64229?
CVE-2025-64229 is classified as a missing authorization vulnerability that can lead to unauthorized access and exploitation.
What versions are affected by CVE-2025-64229?
CVE-2025-64229 affects all versions of Client Invoicing by Sprout Invoices up to and including version 20.8.7.
How do I fix CVE-2025-64229?
To fix CVE-2025-64229, update the Client Invoicing by Sprout Invoices plugin to the latest version that addresses the authorization issues.
What type of vulnerability is CVE-2025-64229?
CVE-2025-64229 is a missing authorization vulnerability caused by incorrectly configured access control security levels.
Who is impacted by CVE-2025-64229?
Users of Client Invoicing by Sprout Invoices and WordPress installations utilizing the plugin are impacted by CVE-2025-64229.