Authorization Flaw in Client Invoicing by Sprout Invoices Affects WordPress
CVE-2026-57418
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 July 2026
What is CVE-2026-57418?
A vulnerability in the Client Invoicing plugin by Sprout Invoices leads to missing authorization controls, allowing unauthorized users to exploit incorrectly configured access rights. This issue affects versions up to and including 20.8.13. Website owners using this plugin should urgently review their access controls to prevent unauthorized access to sensitive client invoicing information.
Affected Version(s)
Client Invoicing by Sprout Invoices 0 <= 20.8.13