Impact
Unsecured direct object references in the Sprout Invoices plugin allow unauthenticated users to request invoice identifiers and retrieve details that they are not permitted to view. This flaw stems from missing authorization checks when resolving invoice objects, categorized as CWE‑639. An attacker could potentially enumerate invoice IDs and access sensitive information such as billing details, payment status, and client data, compromising confidentiality and integrity.
Affected Systems
The vulnerability impacts WordPress sites that have the BoldGrid Client Invoicing by Sprout Invoices plugin installed at versions 20.8.17 or earlier. These sites may provide invoice related endpoints that expose invoice data to any visitor.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk. No EPSS score is currently available, and the vulnerability is not listed in CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector is remote through a web request, meaning any publicly accessible WordPress installation with the vulnerable plugin could be exploited by an attacker who can guess or enumerate invoice identifiers. The exploit does not require authentication, making it readily available to adversaries with internet connectivity.
OpenCVE Enrichment