InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure

2024-02-08 00:00
Christian Angel

Strategic Overview

Status
Patched in 1.12.3.1
Affected PluginInfiniteWP Client
Affected Version<= 1.12.3
CVSS5.9Medium
CVECVE-2023-6565
View all InfiniteWP Client vulnerabilities

Vulnerability Overview

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

Technical Analysis

REMEDIATION: Update to version 1.12.3.1, or a newer patched version --- IDENTIFIER: CWE-922 (Insecure Storage of Sensitive Information) The product stores sensitive information without properly limiting read or write access by unauthorized actors.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C