vendor:
Wordpress Plugin InfiniteWP Client
by:
Raphael Karger
8.8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Wordpress Plugin InfiniteWP Client
Affected Version From: InfiniteWP Client < 1.9.4.5
Affected Version To: InfiniteWP Client < 1.9.4.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
WordPress Plugin InfiniteWP Client 1.9.4.5 – Authentication Bypass
An authentication bypass vulnerability exists in Wordpress Plugin InfiniteWP Client version 1.9.4.5 and prior. An attacker can exploit this vulnerability to bypass authentication and gain access to the application. This is achieved by sending a specially crafted HTTP request to the vulnerable application. The request contains a specially crafted JSON payload that is base64 encoded and sent as part of the request. This payload contains a username parameter that is used to bypass authentication.
Mitigation:
Upgrade to InfiniteWP Client version 1.9.4.5 or later.