CVE-2026-39562: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.10 - Broken Access Control vulnerability
Published Apr 8, 2026
·Updated
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10.
Affected Software
1 affected component
Sprout Invoices Client Invoicing by Sprout Invoices<=20.8.10
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible and requires no privileges or user interaction. Attack complexity is rated low.
2
What is the expected impact if exploitation succeeds?
The reported CVSS impact is limited to low integrity impact. No confidentiality or availability impact is reported.
3
Which plugin versions should be considered affected?
Client Invoicing by Sprout Invoices versions through 20.8.10 are listed as affected. The available data does not specify a lower affected version boundary.