InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
2024-02-08 00:00
Christian AngelStrategic Overview
StatusPatched in 1.12.3.1
Affected PluginInfiniteWP Client
Affected Version
<= 1.12.3CVSS5.9Medium
CVE
CVE-2023-6565Vulnerability Overview
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Technical Analysis
REMEDIATION: Update to version 1.12.3.1, or a newer patched version --- IDENTIFIER: CWE-922 (Insecure Storage of Sensitive Information) The product stores sensitive information without properly limiting read or write access by unauthorized actors.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C