Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection.

This issue affects InfiniteWP Client: from n/a through 1.13.9.
Published: 2026-08-20
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in an SQL command is present in the InfiniteWP Client plugin, enabling a blind SQL injection. The flaw can be exploited to manipulate database queries and retrieve or modify sensitive information without authentication, if access to the vulnerable input is available.

Affected Systems

The vulnerability affects the revmakx InfiniteWP Client plugin deployed in WordPress sites. Any installation of the plugin from any version up to and including 1.13.9 is susceptible; newer releases are not listed as affected.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity. No EPSS data is available, and the flaw is not currently listed in CISA KEV. Attackers would need to supply crafted input to the plugin’s parameters, which could be achieved through normal site interactions or by targeting administrative pages. The lack of authentication bypass in the description suggests that the vector might be limited to authenticated users or exposed administrative endpoints, but the exact conditions are not explicitly stated in the advisory.

Generated by OpenCVE AI on August 20, 2026 at 20:43 UTC.

Remediation

Vendor Solution

Update the WordPress InfiniteWP Client Plugin to the latest available version (at least 1.13.10).


OpenCVE Recommended Actions

  • Update the WordPress InfiniteWP Client plugin to version 1.13.10 or later as released by the vendor.
  • Limit access to the plugin’s configuration and callback interfaces to trusted administrative users only, ensuring that unprivileged users cannot submit input that is processed by the vulnerable code.
  • Monitor Web and database logs for unusual query patterns or repeated attempts to inject SQL via the plugin’s endpoints, and configure alerts to detect potential exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Revmakx
Revmakx infinitewp Client
Wordpress
Wordpress wordpress
Vendors & Products Revmakx
Revmakx infinitewp Client
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
Title WordPress InfiniteWP Client plugin <= 1.13.9 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Revmakx Infinitewp Client
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:27.196Z

Reserved: 2026-08-14T10:16:11.319Z

Link: CVE-2026-74011

cve-icon Vulnrichment

Updated: 2026-08-20T16:19:03.421Z

cve-icon NVD

Status : Received

Published: 2026-08-20T13:19:05.710

Modified: 2026-08-20T17:19:41.760

Link: CVE-2026-74011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')