cleantalk
Vulnerabilities and Security Researches

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress, CVE-2025-24606

CVE, Research URL

CVE-2025-24606

Published on
Jan 27, 2025
Research Description
Missing Authorization vulnerability in Sprout Invoices Client Invoicing by Sprout Invoices allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Client Invoicing by Sprout Invoices: from n/a through 20.8.1.
Affected versions
max 20.8.2.
Status
vulnerable