CVE-2023-6565: InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6565?
CVE-2023-6565 is considered a moderate severity vulnerability due to the potential for unauthenticated attackers to access sensitive information.
How do I fix CVE-2023-6565?
To mitigate CVE-2023-6565, update the InfiniteWP Client plugin to version 1.12.4 or later.
What kind of information is exposed in CVE-2023-6565?
CVE-2023-6565 exposes sensitive information that may be contained in a temporary SQL file.
Which versions of InfiniteWP Client are affected by CVE-2023-6565?
CVE-2023-6565 affects all versions of InfiniteWP Client up to and including version 1.12.3.
Can CVE-2023-6565 be exploited without authentication?
Yes, CVE-2023-6565 can be exploited by unauthorized, unauthenticated attackers.