Extension WordPress
Vulnérabilités Sprout Invoices – Client Invoicing & Estimates
Cette page rassemble les failles publiées pour Sprout Invoices – Client Invoicing & Estimates, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Sprout Invoices – Client Invoicing & Estimates
11 fiches
Sprout Invoices – Client Invoicing & Estimates <= 20.8.13 – Missing Authorization
The Sprout Invoices – Client Invoicing & Estimates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.13. This makes it possible for authenticated…
*-20.8.13
20.8.14
08/07/2026
Client Invoicing by Sprout Invoices <= 20.8.10 – Missing Authorization
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.10. This makes it possible for unauthenticated attackers to…
*-20.8.10
20.8.11
19/03/2026
Client Invoicing by Sprout Invoices <= 20.8.9 – Authenticated (Author+) Local File Inclusion
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 20.8.9. This makes it possible for authenticated attackers, with author-level access and above, to include and execute…
*-20.8.9
20.8.10
21/02/2026
Client Invoicing by Sprout Invoices <= 20.8.8 – Missing Authorization
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 20.8.8. This makes it possible for unauthenticated attackers to…
*-20.8.8
20.8.9
15/02/2026
Client Invoicing by Sprout Invoices <= 20.8.7 – Missing Authorization
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 20.8.7.…
*-20.8.7
20.8.8
24/10/2025
Client Invoicing by Sprout Invoices <= 20.8.7 – Unauthenticated PHP Object Injection
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 20.8.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP…
*-20.8.7
20.8.8
02/09/2025
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices <= 20.8.1 – Missing Authorization
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the maybe_change_status() function in all versions up to,…
*-20.8.1
20.8.2
22/12/2024
Client Invoicing by Sprout Invoices <= 20.8.0 – Insecure Direct Object Reference
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 20.8.0 due to missing validation on a user…
*-20.8.0
20.8.1
02/12/2024
Sprout Invoices <= 20.5.3 – Sensitive Information Exposure
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for…
[*, 20.5.4)
20.5.4
13/11/2023
Client Invoicing by Sprout Invoices <= 19.9.6 – Authenticated Stored Cross-Site Scripting
The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5 due to the plugin not sanitising and escaping some of its settings. This makes it possible…
[*, 19.9.7)
19.9.7
18/10/2021
Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress <= 9.3 – Missing Authorization
The Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 9.3. This is due to various missing capability & nonce checks…
*-9.3
9.4
09/02/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.