CVE-2020-8772: Critical severity Revmakx Infinitewp Client Wordpress vulnerability
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwpmmbsetrequest in init.php. Any attacker who knows the username of an administrator can log in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8772?
CVE-2020-8772 is considered a high severity vulnerability due to the ease with which attackers can exploit it to gain unauthorized access.
How do I fix CVE-2020-8772?
To fix CVE-2020-8772, update the InfiniteWP Client plugin to version 1.9.4.5 or later.
Who is affected by CVE-2020-8772?
All users of the InfiniteWP Client plugin prior to version 1.9.4.5 are affected by CVE-2020-8772.
What are the consequences of exploiting CVE-2020-8772?
Exploiting CVE-2020-8772 allows an attacker to log in as an administrator without proper authorization, potentially leading to full site control.
How can I determine if my site is vulnerable to CVE-2020-8772?
You can determine if your site is vulnerable to CVE-2020-8772 by checking if the InfiniteWP Client plugin version is older than 1.9.4.5.