cleantalk
Vulnerabilities and Security Researches

InfiniteWP Client, CVE-2023-6565

CVE, Research URL

CVE-2023-6565

Application

InfiniteWP Client

Published on
Feb 29, 2024
Research Description
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Affected versions
Min -, max 1.12.3.1.
Status
vulnerable