Sensitive Information Exposure in InfiniteWP Client Plugin for WordPress
CVE-2023-6565
5.9MEDIUM
What is CVE-2023-6565?
The InfiniteWP Client plugin for WordPress is susceptible to a vulnerability that allows unauthorized parties to access sensitive information. This exposure occurs through the multi-call backup option, enabling attackers to exploit temporary SQL files during the backup process. By crafting repeated GET requests within a specific timeframe, attackers can potentially extract confidential data, posing significant security risks for WordPress users relying on this plugin. It is crucial for users to upgrade to a secure version to mitigate this risk.
Affected Version(s)
InfiniteWP Client * <= 1.12.3