CVE-2026-32401: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32401?
CVE-2026-32401 is classified as a critical vulnerability due to its potential for local file inclusion and remote exploitation.
How do I fix CVE-2026-32401?
To fix CVE-2026-32401, update the Sprout Invoices plugin to version 20.9.0 or later.
What systems are affected by CVE-2026-32401?
CVE-2026-32401 affects WordPress sites using the Sprout Invoices plugin version 20.8.9 and earlier.
What is the impact of CVE-2026-32401?
The impact of CVE-2026-32401 includes potential unauthorized file access and exposure of sensitive data.
Is there a patch available for CVE-2026-32401?
Yes, there is a patch available by updating the Sprout Invoices plugin to the latest version.