CVE-2025-64229

WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.7 - Broken Access Control vulnerability

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.


We have discovered 305 live websites that are affected by CVE-2025-64229.

Run a Free Instant Scan




Affected Software

Product  Sprout Invoices
Category Wordpress Plugins
Vulnerable Domains305 live websites (71% of Sprout Invoices install base)
Vulnerable Versions
  • from 0 through 20.8.7
Vulnerable Versions Count39 versions ( 91% of all versions)



Details

  • Published - Oct 29, 2025
  • Updated - Apr 1, 2026

Credits

  • Trương Hữu Phúc (truonghuuphuc) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-64229
United States175 websites



GB30 websites
France17 websites
Australia8 websites
Canada8 websites
Cyprus8 websites
Switzerland7 websites
Germany6 websites
South Africa4 websites

Website Distribution by TLD

Number of websites using CVE-2025-64229
.com205 websites
.co.uk12 websites
.net8 websites
.fr7 websites
.com.au6 websites
.ca5 websites
.org5 websites
.ch3 websites
.co2 websites
.cz2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-64229

Top websites that are affected by CVE-2025-64229. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
*******.****.es Spain**,***
************.com United States***,***
******************.com United States***,***
**********.com United States***,***
*******************.com United States***,***
******.eu Germany***,***
*************.com United States***,***
******.io United States***,***
*********.com United States*,***,***
See full domain list

FAQ

A total of 305 websites have been identified as vulnerable to CVE-2025-64229, based on global website indexing conducted by WebTechSurvey.
The Sprout Invoices is affected by the CVE-2025-64229 vulnerability.
Sprout Invoices versions up to and including 20.8.7 are vulnerable to CVE-2025-64229.