CVE-2026-87797 PUBLISHED

Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note

Assigner: WPScan
Reserved: 09.09.2026 Published: 12.09.2026 Updated: 12.09.2026

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.

Product Status

Vendor Unknown
Product Sprout Invoices
Versions Default: unaffected
  • affected from 0 to 20.8.16 (excl.)

Credits

  • Usama Arshad finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE