Sensitive Information Exposure in InfiniteWP Client Plugin for WordPress
CVE-2023-6565
5.9MEDIUM
Summary
The InfiniteWP Client plugin for WordPress is susceptible to a vulnerability that allows unauthorized parties to access sensitive information. This exposure occurs through the multi-call backup option, enabling attackers to exploit temporary SQL files during the backup process. By crafting repeated GET requests within a specific timeframe, attackers can potentially extract confidential data, posing significant security risks for WordPress users relying on this plugin. It is crucial for users to upgrade to a secure version to mitigate this risk.
Affected Version(s)
InfiniteWP Client * <= 1.12.3
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Christian Angel