← volver
CVE-2023-6565mediumCWE-922

InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.9epss 0.6%
probabilidad de explotación
0.6%top 53% de las CVE
explotación observada
noninguna fuente lo reporta
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
revmakx · InfiniteWP Client