The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
We have discovered 77 live websites that are affected by CVE-2021-24787.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 77 live websites (18% of Sprout Invoices install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 14 versions ( 33% of all versions) |
| 40 websites | |
| 9 websites | |
| 4 websites | |
| 3 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites |
| .com | 54 websites |
| .fr | 3 websites |
| .co.uk | 2 websites |
| .com.au | 2 websites |
| .es | 2 websites |
| .ch | 1 websites |
| .co | 1 websites |
| .com.br | 1 websites |
| .cz | 1 websites |
| .io | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.****.es | **,*** | ||
| ******************.com | ***,*** | ||
| **********.com | ***,*** | ||
| *******.co | *,***,*** | ||
| *****.com | *,***,*** | ||
| *************.com | *,***,*** | ||
| *******************.it | *,***,*** | ||
| *******************.com | *,***,*** | ||
| *****.com | *,***,*** | ||
| **************.com | *,***,*** |
FAQ