Impact
The InfiniteWP Client plugin for WordPress is vulnerable to SQL injection (CWE-89) through versions up to and including 1.13.9. The flaw stems from insufficient escaping of array‑key names supplied in the JSON request body. The plugin extracts arguments, processes every key, strips an 'iwp_get_comments_' prefix, wraps the remainder in single quotes, and builds an IN clause without using prepared statements. Because JSON keys are read from php://input and are not subjected to magic quotes, quote characters in the keys pass through unchanged, allowing an attacker to inject arbitrary SQL into the query.
Affected Systems
The affected product is InfiniteWP Client (revmakx) for WordPress. Versions 1.13.9 and earlier are impacted. Any site using this plugin and hosting administrators or users with elevated privileges is at risk.
Risk and Exploitability
The CVSS score of 6.5 categorizes the vulnerability as moderate, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must have administrator or higher privileges; they can register a public key via add_site and then send signed get_comments requests with malicious JSON keys, enabling them to append additional SQL queries and extract sensitive database information. Due to the requirement for authenticated admin access, the risk is moderate but still significant for sites with weak admin controls.
OpenCVE Enrichment