CVE-2026-57418
Deferred Deferred - Pending Action

Missing Authorization in BoldGrid Client Invoicing

Vulnerability report for CVE-2026-57418, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sprout_invoices boldgrid_client_invoicing to 20.8.13 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Missing Authorization issue in the BoldGrid Client Invoicing plugin by Sprout Invoices. It arises from incorrectly configured access control security levels, which means that certain actions or data may be accessible without proper permission checks.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the missing authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices (CVE-2026-57418).

Generally, to detect such vulnerabilities, you may need to: Check the installed version of the Sprout Invoices plugin, particularly the BoldGrid Client Invoicing component, to see if it falls within the affected range (<= 20.8.13).

  • Review access control configurations in the plugin settings to identify misconfigured security levels.
  • Use web application security scanners or tools like WPScan to check for known vulnerabilities in WordPress plugins.

However, without specific detection guidance or resources, these are general recommendations.

Impact Analysis

The vulnerability can allow unauthorized users to access sensitive client invoicing information because the access control is not properly enforced. According to the CVSS score, it has a high impact on confidentiality but does not affect integrity or availability.

Compliance Impact

This vulnerability involves a missing authorization check, which could allow unauthorized access to sensitive data or functionalities within the Client Invoicing by Sprout Invoices plugin. This type of issue can impact compliance with standards and regulations in the following ways:

  • GDPR (General Data Protection Regulation): Unauthorized access to sensitive data, such as customer invoices or personal information, may violate GDPR requirements for data protection and privacy. GDPR mandates strict access controls and safeguards to prevent unauthorized data exposure, and this vulnerability could lead to non-compliance if exploited.
  • HIPAA (Health Insurance Portability and Accountability Act): If the affected system processes or stores protected health information (PHI), this vulnerability could result in unauthorized access to PHI, violating HIPAA's Security Rule. HIPAA requires covered entities to implement access controls to ensure only authorized individuals can access sensitive health data.
  • Other standards: Similar access control requirements exist in other frameworks, such as PCI DSS (Payment Card Industry Data Security Standard) for systems handling payment information. A missing authorization vulnerability could lead to non-compliance if it allows unauthorized access to cardholder data.

Organizations using the affected plugin should assess whether the vulnerability exposes regulated data and take corrective actions to mitigate risks to compliance.

Mitigation Strategies

Based on the provided context, the following immediate steps are recommended to mitigate the vulnerability:

  • Upgrade the Sprout Invoices plugin, specifically the BoldGrid Client Invoicing component, to a version beyond 20.8.13 if available. The context indicates the vulnerability affects versions up to and including 20.8.13.
  • If an update is not immediately available, consider disabling the BoldGrid Client Invoicing feature until a patch is released.
  • Review and enforce proper access control settings for the plugin to ensure only authorized users can access sensitive functionalities.
  • Monitor the plugin vendor's official channels (e.g., website, security advisories) for updates or patches addressing this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57418. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart