Sensitive Information Exposure in InfiniteWP Client Plugin for WordPress
CVE-2023-6565

5.9MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
29 February 2024

Summary

The InfiniteWP Client plugin for WordPress is susceptible to a vulnerability that allows unauthorized parties to access sensitive information. This exposure occurs through the multi-call backup option, enabling attackers to exploit temporary SQL files during the backup process. By crafting repeated GET requests within a specific timeframe, attackers can potentially extract confidential data, posing significant security risks for WordPress users relying on this plugin. It is crucial for users to upgrade to a secure version to mitigate this risk.

Affected Version(s)

InfiniteWP Client * <= 1.12.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Angel
.