PT-2026-95267 · WordPress · Infinitewp Client
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
InfiniteWP Client plugin for WordPress versions prior to 1.14.0
Description
An issue exists in the
get comments action where insufficient escaping of array-key names in the JSON request body allows for SQL Injection. The IWP MMB Comment::get comments() function processes keys by removing the iwp get comments prefix and inserting the remainder into an IN(...) clause executed via $wpdb->get results() without using prepare(). Since the request body is read from php://input and JSON-decoded, wp magic quotes() is bypassed, allowing quote characters in keys to remain unaltered. Authenticated attackers with administrator-level access or higher can exploit this by registering a public key via add site using an activation key to issue signed requests and append malicious SQL queries to extract sensitive database information.Recommendations
Update the InfiniteWP Client plugin for WordPress to version 1.14.0 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinitewp Client