CVE-2026-87797
Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
| Vendor | unknown |
| Product | sprout invoices |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown sprout invoices
Be the first to know when new medium vulnerabilities affecting unknown sprout invoices are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Sprout Invoices
0 < 20.8.16
References
Credits
Usama Arshad WPScan