What the vulnerability does
01Description
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Explanation of Vulnerability in Simple Terms
02Summary
InfiniteWP Client versions up to 1.12.3 contain a vulnerability that allows an attacker to read sensitive information without authentication. The vulnerability requires specific network conditions to exploit but does not require user interaction. No integrity or availability impact occurs. Update to a version newer than 1.12.3 to remediate.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the InfiniteWP Client without authentication.
Potential impact on your site
04Site Impact
Sensitive information stored in or accessible via InfiniteWP Client may be exposed to unauthenticated attackers.
Conditions required to exploit
05Prerequisites
Network access to the affected InfiniteWP Client installation; specific attack complexity conditions must be met.
Key dates
06Disclosure timeline
February 20, 2024
CVE published
April 8, 2026
Record updated