Description
WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create/view clients, payments, estimates and invoices, or save new importer options, including uploading CSVs. WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress version 9.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 9.4 or latest
References
Related Vulnerabilities
WordPress Plugin Twenty20 Image Before-After Malicious Code (1.6.3)
WordPress Plugin WP Visitor Statistics (Real Time Traffic) Unspecified Vulnerability (4.8)
OpenSSL Improper Access Control Vulnerability (CVE-2016-7054)
Drupal Core 8.9.x Cross-Site Scripting (8.9.0 - 8.9.17)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0009)