CVE-2026-25364: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25364?
CVE-2026-25364 is classified as a high severity vulnerability due to its impact on access control.
How do I fix CVE-2026-25364?
To fix CVE-2026-25364, update the Client Invoicing by Sprout Invoices plugin to version 20.8.9 or later.
What type of vulnerability is CVE-2026-25364?
CVE-2026-25364 is a Broken Access Control vulnerability that allows incorrect authorization levels.
Which software is affected by CVE-2026-25364?
CVE-2026-25364 affects the Client Invoicing by Sprout Invoices plugin in versions up to and including 20.8.8.
How can CVE-2026-25364 be exploited?
CVE-2026-25364 can be exploited through incorrectly configured access controls, allowing unauthorized access to sensitive data.