WordPress.InfiniteWP.Client.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass Vulnerability in WordPress InfiniteWP Client Plugin.
A remote, unauthenticated attacker can exploit this vulnerability by directly visiting certain specific pages. Successful exploitation could result in the bypassing of authentication, allowing an attacker to overwrite files in vulnerable system and to execute Remote Code in context of the vulnerable systems.

affected-products-logoAffected Products

WordPress InfiniteWP Client Plugin version 1.9.4.4 and prior

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://wpvulndb.com/vulnerabilities/10011

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-05-14 15.845 Default_action:pass:drop
2020-04-02 15.810

References

10011