The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58793 The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00674}

epss

{'score': 0.00913}


Tue, 25 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Revmakx
Revmakx infinitewp Client
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:revmakx:infinitewp_client:*:*:*:*:*:wordpress:*:*
Vendors & Products Revmakx
Revmakx infinitewp Client

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-04-22T16:24:54.684Z

Reserved: 2023-12-06T22:10:27.105Z

Link: CVE-2023-6565

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.825Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-29T01:42:39.890

Modified: 2025-02-25T22:54:36.040

Link: CVE-2023-6565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.