Back

MEDIUM

InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure

Published Feb 20, 2024

Description

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 20, 2024
Updated Apr 8, 2026
Reserved Dec 6, 2023
CISA Vulnrichment
Updated Mar 5, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Feb 20, 2024
Updated Apr 8, 2026
Exploited since n/a
EUVD-2023-58793