CVE-2026-25364

WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.8 - Broken Access Control vulnerability

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8.


We have discovered 349 live websites that are affected by CVE-2026-25364.

Run a Free Instant Scan




Affected Software

Product  Sprout Invoices
Category Wordpress Plugins
Vulnerable Domains349 live websites (81% of Sprout Invoices install base)
Vulnerable Versions
  • from 0 through 20.8.8
Vulnerable Versions Count40 versions ( 93% of all versions)



Details

  • Published - Feb 19, 2026
  • Updated - Apr 1, 2026

Credits

  • Bao - BlueRock | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-25364
United States205 websites



GB33 websites
France18 websites
Canada11 websites
Cyprus8 websites
Australia8 websites
Germany8 websites
Switzerland7 websites
South Africa5 websites
Sweden3 websites

Website Distribution by TLD

Number of websites using CVE-2026-25364
.com235 websites
.co.uk12 websites
.net12 websites
.fr7 websites
.ca6 websites
.com.au6 websites
.org6 websites
.ch3 websites
.se2 websites
.cz2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25364

Top websites that are affected by CVE-2026-25364. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
*******.****.es Spain**,***
************.com United States***,***
******************.com United States***,***
**********.com United States***,***
*******************.com United States***,***
******.eu Germany***,***
*************.com United States***,***
******.io United States***,***
*********.com United States*,***,***
See full domain list

FAQ

A total of 349 websites have been identified as vulnerable to CVE-2026-25364, based on global website indexing conducted by WebTechSurvey.
The Sprout Invoices is affected by the CVE-2026-25364 vulnerability.
Sprout Invoices versions up to and including 20.8.8 are vulnerable to CVE-2026-25364.