CVE-2026-32401 HIGH

CVE-2026-32401: WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability

Vendor Boldgrid
Product Client Invoicing by Sprout Invoices
Weakness CWE-98 · PHP file inclusion
Published March 13, 2026
Last update April 29, 2026

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.

Explanation of Vulnerability in Simple Terms

02Summary

An authenticated administrator in BoldGrid's Client Invoicing by Sprout Invoices can read, modify, or delete data on the site. The vulnerability requires high-level admin access and affects all versions up to 20.8.9. Update to a version newer than 20.8.9 to remediate.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete site data if they have administrator access.

Potential impact on your site

04Site Impact

A compromised admin account can access, alter, or destroy invoices and related business data.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrator privileges on the site.

Key dates

06Disclosure timeline

March 13, 2026 CVE published
April 29, 2026 Record updated