Description
WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create/view clients, payments, estimates and invoices, or save new importer options, including uploading CSVs. WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress version 9.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 9.4 or latest
References
Related Vulnerabilities
WordPress Plugin WP Humans.txt Cross-Site Scripting (1.0.6)
Liferay DXP CVE-2021-38266 Vulnerability (CVE-2021-38266)
WordPress Plugin Import any XML or CSV File to WordPress Cross-Site Scripting (3.4.5)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16185)
WordPress Plugin ContentStudio Multiple Vulnerabilities (1.2.5)