Description
The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on $args (which silently skips keys that are not valid PHP variable names) but a second foreach($args as $checkbox => $checkbox_val) processes every key, strips the 'iwp_get_comments_' prefix with str_replace(), wraps the remainder in single quotes, and imploded it into an IN(...) clause that is executed via $wpdb->get_results() with no prepare(). Because the request body is read from php://input and JSON-decoded, wp_magic_quotes() never touches the data, so quote characters in keys pass through unaltered. This makes it possible for authenticated attackers, with administrator-level access and above (an administrator can register their own public key via add_site using the plugin's WP-admin-generated activation_key and then issue signed get_comments requests), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Apply Patch
AI Analysis

Impact

The InfiniteWP Client plugin for WordPress is vulnerable to SQL injection (CWE-89) through versions up to and including 1.13.9. The flaw stems from insufficient escaping of array‑key names supplied in the JSON request body. The plugin extracts arguments, processes every key, strips an 'iwp_get_comments_' prefix, wraps the remainder in single quotes, and builds an IN clause without using prepared statements. Because JSON keys are read from php://input and are not subjected to magic quotes, quote characters in the keys pass through unchanged, allowing an attacker to inject arbitrary SQL into the query.

Affected Systems

The affected product is InfiniteWP Client (revmakx) for WordPress. Versions 1.13.9 and earlier are impacted. Any site using this plugin and hosting administrators or users with elevated privileges is at risk.

Risk and Exploitability

The CVSS score of 6.5 categorizes the vulnerability as moderate, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have administrator or higher privileges; they can register a public key via add_site and then send signed get_comments requests with malicious JSON keys, enabling them to append additional SQL queries and extract sensitive database information. Due to the requirement for authenticated admin access, the risk is moderate but still significant for sites with weak admin controls.

Generated by OpenCVE AI on September 19, 2026 at 22:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the InfiniteWP Client plugin to the latest available version, which addresses this vulnerability.
  • If an upgrade cannot be performed immediately, restrict or disable the plugin’s get_comments API endpoint for non‑essential administrators or contractors, limiting exposure to trusted users only.
  • Audit the site's administrator accounts, remove any unused or excessive admin users, and enforce least‑privilege access to minimize potential attackers’ privileges.

Generated by OpenCVE AI on September 19, 2026 at 22:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Revmakx
Revmakx infinitewp Client
Wordpress
Wordpress wordpress
Vendors & Products Revmakx
Revmakx infinitewp Client
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on $args (which silently skips keys that are not valid PHP variable names) but a second foreach($args as $checkbox => $checkbox_val) processes every key, strips the 'iwp_get_comments_' prefix with str_replace(), wraps the remainder in single quotes, and imploded it into an IN(...) clause that is executed via $wpdb->get_results() with no prepare(). Because the request body is read from php://input and JSON-decoded, wp_magic_quotes() never touches the data, so quote characters in keys pass through unaltered. This makes it possible for authenticated attackers, with administrator-level access and above (an administrator can register their own public key via add_site using the plugin's WP-admin-generated activation_key and then issue signed get_comments requests), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Revmakx Infinitewp Client
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T14:31:43.041Z

Reserved: 2026-07-27T15:27:13.910Z

Link: CVE-2026-17576

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:42.796Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:49.643

Modified: 2026-09-18T15:17:06.293

Link: CVE-2026-17576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')