Description
Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
Published: 2026-09-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized data access via insecure direct object references
Action: Immediate update
AI Analysis

Impact

Unsecured direct object references in the Sprout Invoices plugin allow unauthenticated users to request invoice identifiers and retrieve details that they are not permitted to view. This flaw stems from missing authorization checks when resolving invoice objects, categorized as CWE‑639. An attacker could potentially enumerate invoice IDs and access sensitive information such as billing details, payment status, and client data, compromising confidentiality and integrity.

Affected Systems

The vulnerability impacts WordPress sites that have the BoldGrid Client Invoicing by Sprout Invoices plugin installed at versions 20.8.17 or earlier. These sites may provide invoice related endpoints that expose invoice data to any visitor.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate risk. No EPSS score is currently available, and the vulnerability is not listed in CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector is remote through a web request, meaning any publicly accessible WordPress installation with the vulnerable plugin could be exploited by an attacker who can guess or enumerate invoice identifiers. The exploit does not require authentication, making it readily available to adversaries with internet connectivity.

Generated by OpenCVE AI on September 30, 2026 at 16:04 UTC.

Remediation

Vendor Solution

Update the WordPress Client Invoicing by Sprout Invoices plugin to the latest available version (at least 20.8.18).


OpenCVE Recommended Actions

  • Update the WordPress Client Invoicing by Sprout Invoices plugin to version 20.8.18 or newer.
  • If an update is not immediately possible, temporarily disable or restrict public access to invoice endpoints, ensuring only authenticated and authorized users can request invoice data.
  • Verify that every invoice retrieval request validates the requesting user’s ownership or role permissions, preventing IDOR for all pages that expose invoice data.

Generated by OpenCVE AI on September 30, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
Title WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.17 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:07.807Z

Reserved: 2026-09-24T00:20:10.982Z

Link: CVE-2026-97078

cve-icon Vulnrichment

Updated: 2026-09-30T13:19:28.363Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:34.600

Modified: 2026-09-30T14:18:13.920

Link: CVE-2026-97078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key