← WordPress Vulnerabilities
WordPress security by component

InfiniteWP Client

InfiniteWP Client is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jan 08, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: infinitewp-client

CVE-2024-10585: InfiniteWP Client: Filesystem traversal

InfiniteWP Client is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.

PublishedJan 08, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 08, 2025 CVE-2024-10585
InfiniteWP Client: Filesystem traversal
InfiniteWP Client is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE5.3
NVDPending
Feb 29, 2024 CVE-2023-6565
InfiniteWP Client: Sensitive information exposure
InfiniteWP Client is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.9
NVDPending
Jul 23, 2022 CVE-2016-15004
Infinitewp Client: A security weakness
Infinitewp Client is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD9.8
Feb 06, 2020 CVE-2020-8772
Infinitewp Client: A security weakness
Infinitewp Client is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8