CVE-2023-6565 MEDIUM

CVE-2023-6565: InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure

Vendor Revmakx
Product InfiniteWP Client
Weakness CWE-922
Published February 20, 2024
Last update April 8, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

Explanation of Vulnerability in Simple Terms

02Summary

InfiniteWP Client versions up to 1.12.3 contain a vulnerability that allows an attacker to read sensitive information without authentication. The vulnerability requires specific network conditions to exploit but does not require user interaction. No integrity or availability impact occurs. Update to a version newer than 1.12.3 to remediate.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the InfiniteWP Client without authentication.

Potential impact on your site

04Site Impact

Sensitive information stored in or accessible via InfiniteWP Client may be exposed to unauthenticated attackers.

Conditions required to exploit

05Prerequisites

Network access to the affected InfiniteWP Client installation; specific attack complexity conditions must be met.

Key dates

06Disclosure timeline

February 20, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE