cleantalk
Vulnerabilities and Security Researches

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress, CVE-2025-64227

CVE, Research URL

CVE-2025-64227

Published on
Dec 18, 2025
Research Description
Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.
Affected versions
max 20.8.7.
Status
vulnerable