PT-2026-95267 · WordPress · Infinitewp Client

·

CVE-2026-17576

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions InfiniteWP Client plugin for WordPress versions prior to 1.14.0
Description An issue exists in the get comments action where insufficient escaping of array-key names in the JSON request body allows for SQL Injection. The IWP MMB Comment::get comments() function processes keys by removing the iwp get comments prefix and inserting the remainder into an IN(...) clause executed via $wpdb->get results() without using prepare(). Since the request body is read from php://input and JSON-decoded, wp magic quotes() is bypassed, allowing quote characters in keys to remain unaltered. Authenticated attackers with administrator-level access or higher can exploit this by registering a public key via add site using an activation key to issue signed requests and append malicious SQL queries to extract sensitive database information.
Recommendations Update the InfiniteWP Client plugin for WordPress to version 1.14.0 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17576

Affected Products

Infinitewp Client