The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

Project Subscriptions

Vendors Products
Revmakx Subscribe
Infinitewp Client Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58793 The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
Title InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
Weaknesses CWE-922

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00674}

epss

{'score': 0.00913}


Tue, 25 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Revmakx
Revmakx infinitewp Client
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:revmakx:infinitewp_client:*:*:*:*:*:wordpress:*:*
Vendors & Products Revmakx
Revmakx infinitewp Client

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:44:43.545Z

Reserved: 2023-12-06T22:10:27.105Z

Link: CVE-2023-6565

cve-icon Vulnrichment

Updated: 2024-08-02T08:35:14.825Z

cve-icon NVD

Status : Modified

Published: 2024-02-29T01:42:39.890

Modified: 2026-04-08T17:17:14.460

Link: CVE-2023-6565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses