Impact
Missing authorization in the Sprout Invoices plugin allows attackers to exploit incorrectly configured access control security levels, resulting in unauthorized operations against the invoicing system. The flaw is a classic broken access control weakness (CWE-862) that may enable privileged actions for users without proper permissions, potentially exposing sensitive data or permitting malicious financial actions.
Affected Systems
The vulnerability affects the BoldGrid Client Invoicing by Sprout Invoices WordPress plugin versions up to and including 20.8.13. Systems running any of these versions are exposed until updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves interacting with the plugin’s administrative interfaces, potentially by any authenticated user with access to the WordPress site. Exploitation would require the attacker to locate and use the vulnerable endpoint within the plugin, which is presumably accessible without additional network restrictions.
OpenCVE Enrichment