Local File Inclusion Vulnerability in BoldGrid Client Invoicing by Sprout Invoices
CVE-2026-32401

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32401?

The vulnerability in BoldGrid Client Invoicing by Sprout Invoices allows for improper control of filenames in PHP, leading to potential local file inclusion. Attackers may exploit this flaw to access sensitive files on the server, compromising the integrity and confidentiality of the affected system. The issue affects versions of the product from unversioned release up to and including 20.8.9, highlighting a critical need for immediate updates and security measures.

Affected Version(s)

Client Invoicing by Sprout Invoices 0 <= 20.8.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.