A Missing Authorization vulnerability was found in BoldGrid Client Invoicing by Sprout Invoices. This issue, tracked as CVE-2026-57418, allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability affects Client Invoicing by Sprout Invoices versions from n/a through <= 20.8.13. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. It is caused by a M [truncated]
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability exists due to insufficient validation of user-supplied input, allowing attackers to acces [truncated]
CVE-2026-39595 is a medium-severity vulnerability (CVSS score of 4.7) affecting the W3 Total Cache plugin for WordPress, specifically versions up to 2.9.1. The issue is classified as 'Author Broken Access Control,' indicating a problem with access control mechanisms that could allow unauthorized users to perform actions they shouldn't be able to. This vulnerability was made public on June 17, 2026. Given [truncated]