plugin

Iwp Client Vulnerabilities

21 known security issues reported for the Iwp Client WordPress plugin. Most recent disclosed Aug 20, 2026.

4 critical 1 high 3 medium

Running Iwp Client on your site? Check whether your installed version is affected.

Scan your site free

InfiniteWP Client <= 1.13.9 - Authenticated (Administrator+) SQL Injection

medium

The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.13.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator...

CVSS:
4.9
Affected:
up to 1.13.9
Fixed in:
1.13.10
Disclosed:
Aug 20, 2026

CVE-2026-74011 on NVD →

InfiniteWP Client [iwp-client] < 1.13.1

unknown

[en] The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

Affected:
up to 1.13.1
Fixed in:
1.13.1
Disclosed:
Jan 8, 2025

CVE-2024-10585 on NVD →

InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading

medium

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

CVSS:
5.3
Affected:
up to 1.13.0
Fixed in:
1.13.1
Disclosed:
Jan 7, 2025

CVE-2024-10585 on NVD →

InfiniteWP Client [iwp-client] < 1.12.3.1

unknown

[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the lim...

Affected:
up to 1.12.3.1
Fixed in:
1.12.3.1
Disclosed:
Feb 20, 2024

CVE-2023-6565 on NVD →

InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure

medium

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited...

CVSS:
5.9
Affected:
up to 1.12.3
Fixed in:
1.12.3.1
Disclosed:
Feb 8, 2024

CVE-2023-6565 on NVD →

InfiniteWP Client [iwp-client] < 1.12.1

unknown

[en] The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be ex...

Affected:
up to 1.12.1
Fixed in:
1.12.1
Disclosed:
Aug 15, 2023

CVE-2023-2916 on NVD →

InfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure

high

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploit...

CVSS:
7.5
Affected:
up to 1.11.1
Fixed in:
1.12.1
Disclosed:
Aug 14, 2023

CVE-2023-2916 on NVD →

InfiniteWP Client [iwp-client] < 1.6.1.1

unknown

[en] A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended...

Affected:
up to 1.6.1.1
Fixed in:
1.6.1.1
Disclosed:
Jul 23, 2022

CVE-2016-15004 on NVD →

InfiniteWP Client [iwp-client] < 1.9.4.5

unknown

[en] The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

Affected:
up to 1.9.4.5
Fixed in:
1.9.4.5
Disclosed:
Feb 6, 2020

CVE-2020-8772 on NVD →

InfiniteWP Client <= 1.9.4.4 - Authentication Bypass

critical

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVSS:
9.8
Affected:
up to 1.9.4.4
Fixed in:
1.9.4.5
Disclosed:
Jan 14, 2020

CVE-2020-8772 on NVD →

InfiniteWP Client [iwp-client] < 1.9.4.5

unknown

Authentication Bypass vulnerability found by WebARX in WordPress InfiniteWP Client plugin (versions <= 1.9.4.4).

Affected:
up to 1.9.4.5
Fixed in:
1.9.4.5
Disclosed:
Jan 8, 2020

InfiniteWP Client <= 1.6.0 - Unauthenticated PHP Object Injection

critical

The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.0 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the site.

CVSS:
9.8
Affected:
up to 1.6.1.1
Fixed in:
1.6.1.1
Disclosed:
Jan 25, 2017

CVE-2016-15004 on NVD →

InfiniteWP Client [iwp-client] < 1.3.15

unknown

There is an unknown issue in this plugin. Update the plugin.

Affected:
up to 1.3.15
Fixed in:
1.3.15
Disclosed:
Jul 8, 2015

InfiniteWP Client <= 1.3.7 - Privilege Escalation

critical

The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to put the vulnerable site into maintenance mode if the admin's username is known.

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Dec 2, 2014

InfiniteWP Client <= 1.3.7 - PHP Object Injection

critical

The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object which can result in subsequent attacks Remote Code Injection, SQL Injection, Path Traversal, etc w...

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Dec 2, 2014

InfiniteWP Client [iwp-client] < 1.3.8

unknown

The InfiniteWP Client plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.7 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object which can result in subsequent attacks Remote Code Injection, SQL Injection, Path Traversal, etc w...

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Dec 2, 2014

InfiniteWP Client [iwp-client] < 1.3.8

unknown

The InfiniteWP Client plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to put the vulnerable site into maintenance mode if the admin's username is known.

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Dec 2, 2014

InfiniteWP Client [iwp-client] < 1.3.8

unknown

Because of this vulnerability, Javascript or iframe malware, spam links or defacement messages could be injected. Upgrade the plugin.

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Dec 2, 2014

InfiniteWP Client [iwp-client] < 1.6.1.1

unknown

The InfiniteWP Client WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.

Affected:
up to 1.6.1.1
Fixed in:
1.6.1.1

InfiniteWP Client [iwp-client] < 1.3.15

unknown

The InfiniteWP Client WordPress plugin was affected by an Unspecified Critical security vulnerability.

Affected:
up to 1.3.15
Fixed in:
1.3.15

InfiniteWP Client [iwp-client] < 1.3.8

unknown

The InfiniteWP Client WordPress plugin was affected by a Privilege Escalation security vulnerability.

Affected:
up to 1.3.8
Fixed in:
1.3.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database