Impact
The Sprout Invoices WordPress plugin version 20.8.16 or earlier allows any authenticated user to overwrite private notes attached to invoicing records because the AJAX endpoint si_edit_private_note lacks a capability or ownership check. A subscriber can replace the content of a note belonging to another user, thereby undermining data integrity and breaching confidentiality of invoicing information. This flaw aligns with CWE-862, a missing authorization check.
Affected Systems
All installations of Sprout Invoices with a version earlier than 20.8.16 are affected. The attack is independent of the WordPress site version and targets any site that has the plugin installed and has enabled the AJAX endpoint for private note editing. Users with login access, such as subscribers or authors, can exploit the vulnerability if they have permission to trigger the endpoint.
Risk and Exploitability
Exploitation requires only authenticated access and the ability to send an AJAX request to si_edit_private_note. No privilege escalation is needed beyond normal login rights. The CVSS base score of 4.3 indicates moderate severity focused on data integrity, and the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks.
OpenCVE Enrichment