CVE-2026-87797: CWE-862 Missing Authorization in Sprout Invoices
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
AI Analysis
Technical Summary
The Sprout Invoices WordPress plugin versions prior to 20.8.16 do not verify user capabilities or ownership before permitting the overwriting of private notes via an AJAX action. This missing authorization (CWE-862) enables any authenticated user, regardless of privilege level, to modify private notes on other users' records.
Potential Impact
An authenticated user with minimal privileges can overwrite private notes on records owned by other users. This could lead to unauthorized modification of sensitive information stored in private notes, potentially impacting data integrity and confidentiality within the application.
Mitigation Recommendations
Upgrade Sprout Invoices to version 20.8.16 or later, where this authorization issue has been fixed. No other mitigation is necessary once the plugin is updated.
CVE-2026-87797: CWE-862 Missing Authorization in Sprout Invoices
Description
The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.
CVSS v3.1
Score 4.3medium
Affected software
Sprout Invoices
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Sprout Invoices WordPress plugin versions prior to 20.8.16 do not verify user capabilities or ownership before permitting the overwriting of private notes via an AJAX action. This missing authorization (CWE-862) enables any authenticated user, regardless of privilege level, to modify private notes on other users' records.
Potential Impact
An authenticated user with minimal privileges can overwrite private notes on records owned by other users. This could lead to unauthorized modification of sensitive information stored in private notes, potentially impacting data integrity and confidentiality within the application.
Mitigation Recommendations
Upgrade Sprout Invoices to version 20.8.16 or later, where this authorization issue has been fixed. No other mitigation is necessary once the plugin is updated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-09T09:53:25.383Z
- State
- PUBLISHED
Threat ID: 6aa4ee6355bf5e2cf5f21ff7
Added to database: 09/12/2026, 06:17:07 UTC
Last enriched: 09/12/2026, 06:32:43 UTC
Last updated: 09/13/2026, 02:07:08 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.