CVE-2026-32401
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-32401 is a Local File Inclusion (LFI) vulnerability in the BoldGrid "Client Invoicing by Sprout Invoices" WordPress plugin. It affects all versions up to and including 20.8.9, and was reported on January 22, 2026, with public disclosure on February 21, 2026 via Patchstack. The vulnerability carries a CVSS v3.1 base score of 7.2 (High), requiring high privileges (Author/Developer level) for exploitation (Patchstack).

Technical details

The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which enables PHP Local File Inclusion. The vulnerability arises from insufficient validation of user-supplied input used in PHP include/require statements within the plugin, allowing an attacker with Author or Developer-level WordPress privileges to manipulate file path parameters and force the server to include arbitrary local files. Exploitation occurs over the network with low attack complexity and requires no user interaction beyond the attacker's own authenticated session (Patchstack).

Impact

Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php (which contains database credentials), potentially leading to complete database takeover. High confidentiality, integrity, and availability impacts are possible if credential files are exposed and leveraged for further access. The scope is limited to the affected system, but lateral movement within the hosting environment is feasible if database or system credentials are obtained (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.00138 (0.138%), indicating a low probability of exploitation in the near term. The vulnerability requires high privileges (Author/Developer role), which limits the attacker pool. Patchstack classifies this as low priority with no impactful threat currently observed, and it does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Client Invoicing by Sprout Invoices" plugin at version 20.8.9 or earlier using tools like WPScan or Shodan.
  2. Obtain Privileged Access: Acquire Author or Developer-level credentials on the target WordPress site through phishing, credential stuffing, or brute force.
  3. Identify Vulnerable Parameter: Locate the plugin functionality that accepts a filename or path parameter passed to a PHP include/require statement.
  4. Craft LFI Payload: Manipulate the vulnerable parameter with a path traversal sequence (e.g., ../../../../wp-config.php) to reference a sensitive local file.
  5. Retrieve Sensitive Data: Submit the crafted request and observe the server response, which may render the contents of the included file (e.g., database credentials from wp-config.php).
  6. Escalate Access: Use exposed credentials to access the database directly or escalate privileges within the WordPress environment for further compromise (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing unusual GET/POST requests to Sprout Invoices plugin endpoints containing path traversal sequences (e.g., ../, ..%2F, or encoded variants) in file-related parameters.
  • Logs: PHP error logs referencing unexpected file inclusion attempts or include/require failures for files outside the plugin directory.
  • File System: Unexpected access timestamps on sensitive files such as wp-config.php, /etc/passwd, or other system configuration files.
  • Network: Outbound connections from the web server to unknown external hosts following authenticated plugin interactions, which may indicate chained exploitation.

Mitigation and workarounds

The vendor has released version 20.8.10 of the "Client Invoicing by Sprout Invoices" plugin, which patches this vulnerability. Site administrators should update to version 20.8.10 or later immediately via the WordPress plugin dashboard. If an immediate update is not possible, restrict Author/Developer role assignments to trusted users only, and consider using Patchstack's virtual patching feature to block exploitation attempts until the update can be applied (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through its Active VDP program, classifies it as low priority with unlikely exploitation impact. The vulnerability was reported by researcher "daroo" on January 22, 2026, and publicly disclosed on February 21, 2026. No significant broader media coverage or notable community discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-81648CRITICAL10
  • cryptopayment-gateway
NoNoSep 13, 2026
CVE-2026-88793HIGH8.8
  • youram-youtube-embed
NoNoSep 13, 2026
CVE-2026-85129HIGH8.8
  • hoo-companion
NoNoSep 13, 2026
CVE-2026-88802HIGH7.5
  • mobile-events-manager
NoYesSep 13, 2026
CVE-2026-89050MEDIUM4.3
  • quick-adsense-reloaded
NoYesSep 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management