Impact
This vulnerability is a missing authorization flaw that allows attackers to bypass incorrectly configured access control rules within the Sprout Invoices plugin. By exploiting this weakness, an attacker could gain unauthorized privileges to view, modify, or delete invoice information, potentially exposing sensitive customer data, undermining data integrity, and enabling further attacks within the WordPress environment. The weakness is identified as CWE-862, reflecting an issue where the system does not properly enforce access controls for authenticated users.
Affected Systems
The Sprout Invoices plugin for WordPress, supplied by BoldGrid under the name Client Invoicing by Sprout Invoices, is affected in all releases from its initial version through and including 20.8.8.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating medium severity, and an EPSS score of less than 1%, suggesting low exploitation probability at present. It is not listed in the CISA KEV catalog. The attack vector is likely via the web interface of the WordPress site; an attacker who can access the plugin’s management pages without proper authentication can exploit the broken access control to obtain elevated rights.
OpenCVE Enrichment