CVE-2026-32401

WordPress Client Invoicing by Sprout Invoices plugin <= 20.8.9 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9.


We have discovered 368 live websites that are affected by CVE-2026-32401.

Run a Free Instant Scan




Affected Software

Product  Sprout Invoices
Category Wordpress Plugins
Vulnerable Domains368 live websites (86% of Sprout Invoices install base)
Vulnerable Versions
  • from 0 through 20.8.9
Vulnerable Versions Count41 versions ( 95% of all versions)



Details

  • Published - Mar 13, 2026
  • Updated - Apr 1, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32401
United States215 websites



GB36 websites
France19 websites
Canada13 websites
Cyprus8 websites
Australia8 websites
Germany8 websites
Switzerland8 websites
South Africa5 websites

Website Distribution by TLD

Number of websites using CVE-2026-32401
.com247 websites
.co.uk14 websites
.net13 websites
.fr7 websites
.ca7 websites
.com.au6 websites
.org6 websites
.ch4 websites
.se2 websites
.cz2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32401

Top websites that are affected by CVE-2026-32401. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
*******.****.es Spain**,***
************.com United States***,***
******************.com United States***,***
*******.com United States***,***
**********.com United States***,***
*******************.com United States***,***
******.eu Germany***,***
*************.com United States***,***
******.io United States***,***
See full domain list

FAQ

A total of 368 websites have been identified as vulnerable to CVE-2026-32401, based on global website indexing conducted by WebTechSurvey.
The Sprout Invoices is affected by the CVE-2026-32401 vulnerability.
Sprout Invoices versions up to and including 20.8.9 are vulnerable to CVE-2026-32401.