๐Ÿ” CVE Alert

CVE-2026-87797

MEDIUM 4.3

Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.

Vendor unknown
Product sprout invoices
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown sprout invoices

Be the first to know when new medium vulnerabilities affecting unknown sprout invoices are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Sprout Invoices
0 < 20.8.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/ded55e47-568d-4702-b043-4707e4182a09/

Credits

Usama Arshad WPScan