Description
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
Published: 2026-09-12
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Modification of Private Notes
Action: Patch Now
AI Analysis

Impact

The Sprout Invoices WordPress plugin version 20.8.16 or earlier allows any authenticated user to overwrite private notes attached to invoicing records because the AJAX endpoint si_edit_private_note lacks a capability or ownership check. A subscriber can replace the content of a note belonging to another user, thereby undermining data integrity and breaching confidentiality of invoicing information. This flaw aligns with CWE-862, a missing authorization check.

Affected Systems

All installations of Sprout Invoices with a version earlier than 20.8.16 are affected. The attack is independent of the WordPress site version and targets any site that has the plugin installed and has enabled the AJAX endpoint for private note editing. Users with login access, such as subscribers or authors, can exploit the vulnerability if they have permission to trigger the endpoint.

Risk and Exploitability

Exploitation requires only authenticated access and the ability to send an AJAX request to si_edit_private_note. No privilege escalation is needed beyond normal login rights. The CVSS base score of 4.3 indicates moderate severity focused on data integrity, and the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks.

Generated by OpenCVE AI on September 15, 2026 at 18:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Sprout Invoices to version 20.8.16 or later, which adds proper capability checks for private note editing.
  • If an upgrade is not immediately possible, restrict the si_edit_private_note AJAX endpoint to administrators by using a role‑management plugin or custom code that verifies the user’s role before accepting the request.
  • As an interim safeguard, disable the plugin’s private note editing feature or the entire plugin until the patch is applied, or switch to a different invoicing solution.

Generated by OpenCVE AI on September 15, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-639

Sat, 12 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
Title Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-12T15:30:13.007Z

Reserved: 2026-09-09T09:53:25.383Z

Link: CVE-2026-87797

cve-icon Vulnrichment

Updated: 2026-09-12T15:16:50.667Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T06:16:27.660

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-87797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:45:18Z

Weaknesses