The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure | |
| Weaknesses | CWE-922 |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 25 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Revmakx
Revmakx infinitewp Client |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:revmakx:infinitewp_client:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Revmakx
Revmakx infinitewp Client |
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-02-20T18:56:24.911Z
Updated: 2026-04-08T16:44:43.545Z
Reserved: 2023-12-06T22:10:27.105Z
Link: CVE-2023-6565
Updated: 2024-08-02T08:35:14.825Z
Status : Modified
Published: 2024-02-29T01:42:39.890
Modified: 2026-04-08T17:17:14.460
Link: CVE-2023-6565
No data.