The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 25 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revmakx
Revmakx infinitewp Client |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:revmakx:infinitewp_client:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Revmakx
Revmakx infinitewp Client |
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-02-20T18:56:24.911Z
Updated: 2025-04-22T16:24:54.684Z
Reserved: 2023-12-06T22:10:27.105Z
Link: CVE-2023-6565
Updated: 2024-08-02T08:35:14.825Z
Status : Analyzed
Published: 2024-02-29T01:42:39.890
Modified: 2025-02-25T22:54:36.040
Link: CVE-2023-6565
No data.