InfiniteWP Client <= 1.13.9 - Authenticated (Administrator+) SQL Injection
medium
The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.13.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator...
- CVSS:
- 4.9
- Affected:
- up to 1.13.9
- Fixed in:
- 1.13.10
- Disclosed:
- Aug 20, 2026
CVE-2026-74011 on NVD →
InfiniteWP Client [iwp-client] < 1.13.1
unknown
[en] The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
- Affected:
- up to 1.13.1
- Fixed in:
- 1.13.1
- Disclosed:
- Jan 8, 2025
CVE-2024-10585 on NVD →
InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading
medium
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
- CVSS:
- 5.3
- Affected:
- up to 1.13.0
- Fixed in:
- 1.13.1
- Disclosed:
- Jan 7, 2025
CVE-2024-10585 on NVD →
InfiniteWP Client [iwp-client] < 1.12.3.1
unknown
[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the lim...
- Affected:
- up to 1.12.3.1
- Fixed in:
- 1.12.3.1
- Disclosed:
- Feb 20, 2024
CVE-2023-6565 on NVD →
InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
medium
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited...
- CVSS:
- 5.9
- Affected:
- up to 1.12.3
- Fixed in:
- 1.12.3.1
- Disclosed:
- Feb 8, 2024
CVE-2023-6565 on NVD →
InfiniteWP Client [iwp-client] < 1.12.1
unknown
[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be ex...
- Affected:
- up to 1.12.1
- Fixed in:
- 1.12.1
- Disclosed:
- Aug 15, 2023
CVE-2023-2916 on NVD →
InfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure
high
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploit...
- CVSS:
- 7.5
- Affected:
- up to 1.11.1
- Fixed in:
- 1.12.1
- Disclosed:
- Aug 14, 2023
CVE-2023-2916 on NVD →
InfiniteWP Client [iwp-client] < 1.6.1.1
unknown
[en] A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended...
- Affected:
- up to 1.6.1.1
- Fixed in:
- 1.6.1.1
- Disclosed:
- Jul 23, 2022
CVE-2016-15004 on NVD →
InfiniteWP Client [iwp-client] < 1.9.4.5
unknown
[en] The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
- Affected:
- up to 1.9.4.5
- Fixed in:
- 1.9.4.5
- Disclosed:
- Feb 6, 2020
CVE-2020-8772 on NVD →
InfiniteWP Client <= 1.9.4.4 - Authentication Bypass
critical
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
- CVSS:
- 9.8
- Affected:
- up to 1.9.4.4
- Fixed in:
- 1.9.4.5
- Disclosed:
- Jan 14, 2020
CVE-2020-8772 on NVD →
InfiniteWP Client [iwp-client] < 1.9.4.5
unknown
Authentication Bypass vulnerability found by WebARX in WordPress InfiniteWP Client plugin (versions <= 1.9.4.4).
- Affected:
- up to 1.9.4.5
- Fixed in:
- 1.9.4.5
- Disclosed:
- Jan 8, 2020
InfiniteWP Client <= 1.6.0 - Unauthenticated PHP Object Injection
critical
The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the site.
- CVSS:
- 9.8
- Affected:
- up to 1.6.1.1
- Fixed in:
- 1.6.1.1
- Disclosed:
- Jan 25, 2017
CVE-2016-15004 on NVD →
InfiniteWP Client [iwp-client] < 1.3.15
unknown
There is an unknown issue in this plugin.
Update the plugin.
- Affected:
- up to 1.3.15
- Fixed in:
- 1.3.15
- Disclosed:
- Jul 8, 2015
InfiniteWP Client <= 1.3.7 - Privilege Escalation
critical
The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to put the vulnerable site into maintenance mode if the admin's username is known.
- CVSS:
- 9.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 2, 2014
InfiniteWP Client <= 1.3.7 - PHP Object Injection
critical
The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object which can result in subsequent attacks Remote Code Injection, SQL Injection, Path Traversal, etc w...
- CVSS:
- 9.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 2, 2014
InfiniteWP Client [iwp-client] < 1.3.8
unknown
The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object which can result in subsequent attacks Remote Code Injection, SQL Injection, Path Traversal, etc w...
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 2, 2014
InfiniteWP Client [iwp-client] < 1.3.8
unknown
The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to put the vulnerable site into maintenance mode if the admin's username is known.
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 2, 2014
InfiniteWP Client [iwp-client] < 1.3.8
unknown
Because of this vulnerability, Javascript or iframe malware, spam links or defacement messages could be injected.
Upgrade the plugin.
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 2, 2014
InfiniteWP Client [iwp-client] < 1.6.1.1
unknown
The InfiniteWP Client WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.
- Affected:
- up to 1.6.1.1
- Fixed in:
- 1.6.1.1
InfiniteWP Client [iwp-client] < 1.3.15
unknown
The InfiniteWP Client WordPress plugin was affected by an Unspecified Critical security vulnerability.
- Affected:
- up to 1.3.15
- Fixed in:
- 1.3.15
InfiniteWP Client [iwp-client] < 1.3.8
unknown
The InfiniteWP Client WordPress plugin was affected by a Privilege Escalation security vulnerability.
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database