Medium 6.5
2026-03-13< 3.2.3
CVE-2026-32424
Minimum safe version
3.2.3
Update to 3.2.3 or later to address 7 fixable vulnerabilities
CVE-2026-32424
CVE-2025-66118
CVE-2025-31797
WordPress Sprout Clients – CRM and Lead Management Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Sprout Clients – CRM and Lead Management plugin <= 3.1 - Sensitive Information Disclosure vulnerability
WordPress Sprout Clients – CRM and Lead Management plugin <= 3.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability