Description
WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create/view clients, payments, estimates and invoices, or save new importer options, including uploading CSVs. WordPress Plugin Client Invoicing by Sprout Invoices-Easy Estimates and Invoices for WordPress version 9.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 9.4 or latest
References
Related Vulnerabilities
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4481)
WordPress Plugin Blue Wrench Video Widget Cross-Site Scripting (2.1.0)
Oracle Database Server Deserialization of Untrusted Data Vulnerability (CVE-2019-16942)
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv Arbitrary File Upload (7.2.6)