CVE-2024-53819

WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.0 - Insecure Direct Object References (IDOR) vulnerability

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.


We have discovered 198 live websites that are affected by CVE-2024-53819.

Run a Free Instant Scan




Affected Software

Product  Sprout Invoices
Category Wordpress Plugins
Vulnerable Domains198 live websites (46% of Sprout Invoices install base)
Vulnerable Versions
  • from 0 through 20.8
Vulnerable Versions Count33 versions ( 77% of all versions)



Details

  • Published - Dec 9, 2024
  • Updated - Apr 1, 2026

Credits

  • Manab Jyoti Dowarah | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2024-53819
United States113 websites



GB21 websites
France10 websites
Australia6 websites
Cyprus6 websites
Canada5 websites
Switzerland5 websites
Italy3 websites
Brazil2 websites
Czech Republic2 websites

Website Distribution by TLD

Number of websites using CVE-2024-53819
.com135 websites
.co.uk7 websites
.fr6 websites
.net5 websites
.com.au4 websites
.ca3 websites
.org3 websites
.com.br2 websites
.cz2 websites
.es2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-53819

Top websites that are affected by CVE-2024-53819. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.****.es Spain**,***
************.com United States***,***
******************.com United States***,***
**********.com United States***,***
*******************.com United States***,***
*************.com United States***,***
**************.online United States*,***,***
******************.**.uk GB*,***,***
*******.co United States*,***,***
********.com United States*,***,***
See full domain list

FAQ

A total of 198 websites have been identified as vulnerable to CVE-2024-53819, based on global website indexing conducted by WebTechSurvey.
The Sprout Invoices is affected by the CVE-2024-53819 vulnerability.
Sprout Invoices versions up to and including 20.8 are vulnerable to CVE-2024-53819.