Impact
Improper neutralization of special elements in an SQL command is present in the InfiniteWP Client plugin, enabling a blind SQL injection. The flaw can be exploited to manipulate database queries and retrieve or modify sensitive information without authentication, if access to the vulnerable input is available.
Affected Systems
The vulnerability affects the revmakx InfiniteWP Client plugin deployed in WordPress sites. Any installation of the plugin from any version up to and including 1.13.9 is susceptible; newer releases are not listed as affected.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. No EPSS data is available, and the flaw is not currently listed in CISA KEV. Attackers would need to supply crafted input to the plugin’s parameters, which could be achieved through normal site interactions or by targeting administrative pages. The lack of authentication bypass in the description suggests that the vector might be limited to authenticated users or exposed administrative endpoints, but the exact conditions are not explicitly stated in the advisory.
OpenCVE Enrichment