Sceawere
Vulnerability Detail
CVE-2026-97078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sprout Invoices Unauthenticated IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 3h ago
- Vendor
- BoldGrid
- Product
- Client Invoicing by Sprout Invoices
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-30T13:17:34.600Z",
"pubdate": "2026-09-30T13:17:34.600Z",
"executiveSummary": "The Sprout Invoices plugin for WordPress is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability affecting versions 20.8.17 and below. This security flaw exists within the client invoicing functionality, allowing unauthenticated remote attackers to bypass access controls.\nThe vulnerability occurs because the application fails to adequately validate the authorization context of requests when accessing sensitive invoice documents. Consequently, an attacker can retrieve, view, or potentially manipulate private billing information by iterating through object identifiers, such as invoice IDs.\nThe impact is significant, as it exposes confidential financial records, client identities, and billing data to unauthorized parties without requiring authentication or administrative privileges. This poses a severe privacy risk and violates data confidentiality requirements. The attack surface is fully exposed over the network, as the vulnerability is accessible via standard HTTP requests. No specialized attacker privileges are required for exploitation, enabling automated mass-scraping of invoice data. Organizations utilizing affected versions are at high risk of data breaches and exposure of PII (Personally Identifiable Information). Remediation requires updating to a patched version once available or implementing strict access control verification routines.",
"technicalDetails": "The vulnerability is rooted in an Insecure Direct Object Reference (IDOR) flaw within the Sprout Invoices plugin codebase. Specifically, the affected component fails to perform server-side checks to verify if the requester has legitimate ownership or authorization to view the requested invoice object.\nThe attack flow commences when an unauthenticated actor identifies the URL structure used to serve invoices to clients. Because the application utilizes predictable or sequential identifiers for invoice objects, an attacker can perform enumeration or 'forced browsing' to identify valid invoice endpoints.\nWhen a request is made to the vulnerable endpoint (typically via a GET request containing an invoice identifier), the application retrieves the requested data from the underlying database or file system and renders the output directly to the user. The backend logic lacks a secondary validation layer that checks the session, nonce, or current user context against the requested object's metadata or associated user ID.\nThe vulnerability resides in the core invoicing delivery mechanism of Sprout Invoices. Because this check is bypassed or absent entirely, the application serves sensitive financial documents to any user who can supply a valid integer or token as an invoice reference. This bypass is possible because the application relies on 'security by obscurity'—assuming that because an invoice URL is complex or unique, it is secure—rather than implementing mandatory access control (MAC) or role-based access control (RBAC) at the function level.\nFrom an exploitation perspective, an attacker can automate the discovery of invoice objects by scripting HTTP requests that iterate through invoice IDs. Once a valid ID is targeted, the application responds with the full invoice content, which may include customer billing details, line items, service descriptions, and total amounts. This post-exploitation outcome grants the attacker unauthorized access to sensitive business-to-business or business-to-consumer financial communication. The vulnerability is effectively a complete failure of authorization, making the system essentially transparent to anyone capable of sending a standard GET request. No specific network configuration is required for exploitation; if the plugin is active and accessible via a web browser, the endpoint is susceptible to remote, unauthenticated access."
}