High severity7.3NVD Advisory· Published Jul 23, 2022· Updated Jun 17, 2026
CVE-2016-15004
CVE-2016-15004
Description
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.
Affected products
4cpe:2.3:a:revmakx:infinitewp_client:1.5.1.3:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:revmakx:infinitewp_client:1.5.1.3:*:*:*:*:wordpress:*:*
- cpe:2.3:a:revmakx:infinitewp_client:1.6.0:*:*:*:*:wordpress:*:*
- Range: <=1.6.0
- unspecified/InfiniteWP Client Pluginv5Range: 1.5.1.3
Patches
Vulnerability mechanics
References
3- seclists.org/fulldisclosure/2017/Jan/72nvdExploitMailing ListThird Party Advisory
- sumofpwn.nl/advisory/2016/infinitewp_client_wordpress_plugin_unauthenticated_php_object_injection_vulnerability.htmlnvdExploitThird Party Advisory
- vuldb.comnvdThird Party Advisory
News mentions
0No linked articles in our index yet.