{"error":0,"message":null,"data":{"name":"InfiniteWP Client","plugin":"iwp-client","link":"https:\/\/wordpress.org\/plugins\/iwp-client\/","latest":"1787157960","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"7bf42ce4964c09edf72f709b4dbb9eb7c5b5f09d29865de7f548438d02479afe","name":"InfiniteWP Client [iwp-client] < 1.9.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-8772","name":"CVE-2020-8772","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-8772","description":"[en] The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.","date":"2020-02-06"},{"id":"e40e0e6cfdf494670d68c89e0a80bf4f82f77997","name":"InfiniteWP Client <= 1.9.4.4 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1944-authentication-bypass","description":"The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.","date":"2020-01-14"},{"id":"fac62d36-0fa1-4b43-8f5c-bddbd0cff140","name":"InfiniteWP Client &lt; 1.9.4.5 - Authentication Bypass","link":"https:\/\/wpscan.com\/vulnerability\/fac62d36-0fa1-4b43-8f5c-bddbd0cff140","description":"As per agreement between the researcher and developer, details will be released on January 14th.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}},{"uuid":"900e0cc9dfe158b6053f04e9d3d89cd43ce745df8ed526c71185156c153c5bbd","name":"InfiniteWP Client [iwp-client] < 1.9.4.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.4.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5d672c01be139e37e36791328d66293f40c4e055","name":"WordPress InfiniteWP Client plugin <= 1.9.4.4 - Authentication Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-9-4-4-authentication-bypass-vulnerability","description":"Authentication Bypass vulnerability found by WebARX in WordPress InfiniteWP Client plugin (versions <= 1.9.4.4).","date":"2020-01-08"}],"impact":[]},{"uuid":"9cb09682acda75018df00c8b3cf39cd4eae8a82c4b7eb2abcace3dce90e74602","name":"InfiniteWP Client [iwp-client] < 1.3.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fbc4a7e0b73fb2da44461bc458b74233a716aa5b","name":"WordPress InfiniteWP Client Plugin <= 1.3.14 - Unspecified Critical","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-3-14-unspecified-critical","description":"There is an unknown issue in this plugin.\nUpdate the plugin.","date":"2015-07-08"}],"impact":[]},{"uuid":"1013aeaad7bdfba7cde1fdd1305f8ae312d5022ccc487b27ca8bd16e6484d612","name":"InfiniteWP Client [iwp-client] < 1.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"cd76ea05f961d70dc07eae9cfeb094be0a7075ca","name":"WordPress InfiniteWP Client Plugin <= 1.3.7 - Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-3-7-privilege-escalation","description":"Because  of this vulnerability, Javascript or iframe malware, spam links or defacement messages could be injected.\nUpgrade the plugin.","date":"2014-12-02"}],"impact":[]},{"uuid":"372c96858c94cf97d34bf50358e59008d10b9c3f602d0c96247140e93359ba0e","name":"InfiniteWP Client [iwp-client] < 1.6.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-15004","name":"CVE-2016-15004","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-15004","description":"[en] A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3\/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.","date":"2022-07-23"},{"id":"e368eb6fa591a84227ba341679f0e89975058100","name":"InfiniteWP Client <= 1.6.0 - Unauthenticated PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-160-unauthenticated-php-object-injection","description":"The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the site.","date":"2017-01-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-74","name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","description":"The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"502870ea4185301ce7398b91a5ac089f325d182641814775aa9ec9b2ee0d9f09","name":"InfiniteWP Client [iwp-client] < 1.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4bb4887bb2db08d9aa5887b2cf5bef3166d3de48","name":"InfiniteWP Client <= 1.3.7 - Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-137-privilege-escalation","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to put the vulnerable site into maintenance mode if the admin's username is known.","date":"2014-12-02"}],"impact":[]},{"uuid":"657163d8afb2c6af34bacfe99aaad80fd9b8973673f18af61a2bed14bd32833e","name":"InfiniteWP Client [iwp-client] < 1.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4413400178a1f156069cf28f5139cff86c80b2b8","name":"InfiniteWP Client <= 1.3.7 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-137-php-object-injection","description":"The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object which can result in subsequent attacks Remote Code Injection, SQL Injection, Path Traversal, etc when a usable gadget is present.","date":"2014-12-02"}],"impact":[]},{"uuid":"b002328099681853f6cab2bbc07dc278104064afbf05632b79beea7240892727","name":"InfiniteWP Client [iwp-client] < 1.6.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e4c6d4bf-69d5-4edd-ae7d-46468373b378","name":"InfiniteWP Client &lt;= 1.6.0 - Unauthenticated PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/e4c6d4bf-69d5-4edd-ae7d-46468373b378","description":"The InfiniteWP Client WordPress plugin was affected by an Unauthenticated PHP Object Injection  security vulnerability.","date":null}],"impact":[]},{"uuid":"60178d3e44ffab53c5cb53e33a36384bbcd5637709081ab8e8dce5b5ae7e1836","name":"InfiniteWP Client [iwp-client] < 1.3.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6064a999-edf1-4654-aa7e-412f6a36b9f9","name":"InfiniteWP Client &lt;= 1.3.14 - Unspecified Critical","link":"https:\/\/wpscan.com\/vulnerability\/6064a999-edf1-4654-aa7e-412f6a36b9f9","description":"The InfiniteWP Client WordPress plugin was affected by an Unspecified Critical  security vulnerability.","date":null}],"impact":[]},{"uuid":"a70518f0502535a15799fcebf33b75bb9a10262898e08fec2a148cbbd1665f38","name":"InfiniteWP Client [iwp-client] < 1.3.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.3.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7e65fbfe-d4f4-42e6-9c1f-f587afeca6a1","name":"InfiniteWP Client &lt;= 1.3.7 - Privilege Escalation","link":"https:\/\/wpscan.com\/vulnerability\/7e65fbfe-d4f4-42e6-9c1f-f587afeca6a1","description":"The InfiniteWP Client WordPress plugin was affected by a Privilege Escalation security vulnerability.","date":null}],"impact":[]},{"uuid":"9ef1d7dcb876b844f7154305b6bf1188822363c48a6047fae445b0ced031586d","name":"InfiniteWP Client [iwp-client] < 1.12.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.12.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-2916","name":"CVE-2023-2916","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-2916","description":"[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.","date":"2023-08-15"},{"id":"8fbeb8f423f0d0bb7a1371f35d21b9a32cdcc066","name":"InfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1111-authenticated-subscriber-sensitive-information-exposure","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.","date":"2023-08-14"},{"id":"3dcb3d3da13e7e6b30959e05805947cc990bfb2b","name":"WordPress  InfiniteWP Client Plugin  <= 1.11.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-11-1-authenticated-subscriber-sensitive-information-exposure-vulnerability","description":"Update the WordPress InfiniteWP Client plugin to the latest available version (at least 1.12.1).\nLana Codes discovered and reported this Sensitive Data Exposure vulnerability in WordPress InfiniteWP Client Plugin.  This vulnerability has been fixed in version 1.12.1.","date":"2023-08-15"},{"id":"714a1a47-25bb-45b6-a9c9-633e382045b7","name":"InfiniteWP Client &lt; 1.12.1 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/714a1a47-25bb-45b6-a9c9-633e382045b7","description":"The plugin exposes sensitive information to unauthenticated users.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"h","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"1.6","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"high","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"1.6","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-668","name":"Exposure of Resource to Wrong Sphere","description":"The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4aa45941909e1cdc70e31add497220fc65114b2bd0d97a8ef177af61ab4f06cb","name":"InfiniteWP Client [iwp-client] < 1.12.3.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.12.3.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6565","name":"CVE-2023-6565","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6565","description":"[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.","date":"2024-02-20"},{"id":"03545023b84bff0310be35b465c827661e78c4b0","name":"InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1123-unauthenticated-sensitive-information-exposure","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.","date":"2024-02-08"},{"id":"4f2a6159019639bb44183422d4dd86892d5a9e8b","name":"WordPress  InfiniteWP Client Plugin  <= 1.12.3 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-12-3-unauthenticated-sensitive-information-exposure-vulnerability","description":"Update the WordPress InfiniteWP Client plugin to the latest available version (at least 1.12.3.1).\nChristian Angel discovered and reported this Sensitive Data Exposure vulnerability in WordPress InfiniteWP Client Plugin.  This vulnerability has been fixed in version 1.12.3.1.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"fcc575b3-0403-484c-b66b-f48a07af61f4","name":"InfiniteWP Client &lt; 1.12.3.1 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/wpscan.com\/vulnerability\/fcc575b3-0403-484c-b66b-f48a07af61f4","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"5.9","severity":"m","exploitable":"2.2","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"5.9","severity":"medium","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.2","impact":"3.6"},"cwe":[{"cwe":"CWE-922","name":"Insecure Storage of Sensitive Information","description":"The product stores sensitive information without properly limiting read or write access by unauthorized actors."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8bb06c3d37a9a44dd5b5a09a490af1da2c1fbff4e1b19c3c78ac6c4defb0c8e9","name":"InfiniteWP Client [iwp-client] < 1.13.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.13.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10585","name":"CVE-2024-10585","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10585","description":"[en] The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~\/debug-chart\/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.","date":"2025-01-08"},{"id":"2c391d7e7e6be0114f3175b88649bac7a49747a5","name":"WordPress InfiniteWP Client Plugin <= 1.13.0 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/iwp-client\/vulnerability\/wordpress-infinitewp-client-plugin-1-13-0-unauthenticated-limited-directory-traversal-to-arbitrary-txt-file-reading-vulnerability","description":"<p>WordPress InfiniteWP Client Plugin <= 1.13.0 is vulnerable to Directory Traversal<\/p><p>Software: InfiniteWP Client<\/p><p>Fixed in version 1.13.1 <\/p><p>Affected Version <= 1.13.0<\/p><p>CVE: CVE-2024-10585<\/p>","date":"2025-01-07"},{"id":"85f590f901fbe4d6928c45516b4f853022a56239","name":"InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1130-unauthenticated-limited-directory-traversal-to-arbitrary-txt-file-reading","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~\/debug-chart\/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.","date":"2025-01-07"},{"id":"EUVD-2024-33519","name":"EUVD-2024-33519","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-33519","description":"The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~\/debug-chart\/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.","date":"2025-01-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.004"}},{"uuid":"7e28c634df17879d92b5841a877896682ecc172b12fcf6ea247faeaa51426982","name":"InfiniteWP Client [iwp-client] < 1.13.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.13.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15038","name":"CVE-2026-15038","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15038","description":"[en] The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.","date":"2026-08-09"},{"id":"EUVD-2026-54882","name":"EUVD-2026-54882","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-54882","description":"The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.","date":"2026-08-09"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b2f9fdf05e132d25544657eeb31f1cb503264e4dcdee2cf1746885c715e5d8c6","name":"InfiniteWP Client [iwp-client] < 1.13.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.13.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-74011","name":"CVE-2026-74011","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74011","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection.\n\nThis issue affects InfiniteWP Client: from n\/a through 1.13.9.","date":"2026-08-20"},{"id":"48eed9cde8fc3d8dfa4f53c6b1d62db7f7697e44","name":"InfiniteWP Client &lt;= 1.13.9 - Authenticated (Administrator+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1139-authenticated-administrator-sql-injection","description":"The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.13.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1bdbd54cb19129e97e6f5665e722e10b9c88f20758aa76759527d8fb4b420c70","name":"InfiniteWP Client [iwp-client] < 1.13.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.13.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-17576","name":"CVE-2026-17576","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-17576","description":"[en] The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on $args (which silently skips keys that are not valid PHP variable names) but a second foreach($args as $checkbox => $checkbox_val) processes every key, strips the 'iwp_get_comments_' prefix with str_replace(), wraps the remainder in single quotes, and imploded it into an IN(...) clause that is executed via $wpdb->get_results() with no prepare(). Because the request body is read from php:\/\/input and JSON-decoded, wp_magic_quotes() never touches the data, so quote characters in keys pass through unaltered. This makes it possible for authenticated attackers, with administrator-level access and above (an administrator can register their own public key via add_site using the plugin's WP-admin-generated activation_key and then issue signed get_comments requests), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-09-18"},{"id":"bdf47859638332b1a9b7f65468f5901d6ac4648a","name":"InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/iwp-client\/infinitewp-client-1139-authenticated-admin-sql-injection-via-iwp-get-comments-array-key","description":"The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on $args (which silently skips keys that are not valid PHP variable names) but a second foreach($args as $checkbox => $checkbox_val) processes every key, strips the 'iwp_get_comments_' prefix with str_replace(), wraps the remainder in single quotes, and imploded it into an IN(...) clause that is executed via $wpdb->get_results() with no prepare(). Because the request body is read from php:\/\/input and JSON-decoded, wp_magic_quotes() never touches the data, so quote characters in keys pass through unaltered. This makes it possible for authenticated attackers, with administrator-level access and above (an administrator can register their own public key via add_site using the plugin's WP-admin-generated activation_key and then issue signed get_comments requests), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789709616"}