CVE-2026-97078: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Direct Object References (IDOR) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
Affected Software
1 affected component
Sprout Invoices Client Invoicing by Sprout Invoices<=20.8.17
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Client Invoicing by Sprout Invoicesto a version that resolves this vulnerability.Fixed in 20.8.18
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and remotely reachable, so an attacker does not need a WordPress account or user interaction to attempt exploitation.
2
What is the likely impact if exploitation succeeds?
The reported CVSS vector indicates low confidentiality impact, with no stated integrity or availability impact. This is consistent with unauthorized access to exposed objects or data through insecure direct references.
3
Which plugin versions are affected?
Client Invoicing by Sprout Invoices versions 20.8.17 and earlier are identified as affected.