
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39562 is a Missing Authorization (Broken Access Control) vulnerability in the BoldGrid "Client Invoicing by Sprout Invoices" WordPress plugin. It affects all versions up to and including 20.8.10, allowing unauthenticated attackers to exploit misconfigured access control security levels. The vulnerability was reported by researcher Bao - BlueRock on February 17, 2026, and published by Patchstack on March 19, 2026, with the CVE record received by NVD on April 8, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning one or more functions within the plugin fail to perform adequate authorization checks before executing privileged actions (Patchstack). The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable remotely. The specific missing check — whether a capability check, nonce validation, or authentication gate — is not publicly detailed, but the flaw allows unauthenticated or low-privileged users to invoke functionality intended for higher-privileged roles within the invoicing plugin.
Successful exploitation results in a low integrity impact, allowing unauthorized modification of invoicing data or business records managed by the plugin, with no direct confidentiality or availability impact per the CVSS scoring (Patchstack). Unauthenticated or low-privileged users could access or manipulate sensitive invoicing data and business records on affected WordPress sites. The scope is limited to the plugin's functionality and does not directly enable lateral movement or full system compromise.
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale, regardless of site popularity (Patchstack).
The vendor (BoldGrid) has released version 20.8.11 of the Client Invoicing by Sprout Invoices plugin, which patches this vulnerability (Patchstack). Site administrators should update to version 20.8.11 or later immediately. If an immediate update is not possible, site owners should consult their hosting provider or web developer, and Patchstack users can enable auto-update for vulnerable plugins as an interim measure.
Patchstack, which discovered and disclosed the vulnerability through its Active VDP program, classifies this as low priority with unlikely exploitation impact (Patchstack). No notable broader media coverage or significant community discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."