Critical severity9.8NVD Advisory· Published Feb 6, 2020· Updated Jun 17, 2026
CVE-2020-8772
CVE-2020-8772
Description
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
Affected products
3- WordPress/InfiniteWP Client plugindescription
- Range: <1.9.4.5
Patches
Vulnerability mechanics
References
2- www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/nvdExploitThird Party Advisory
- wpvulndb.com/vulnerabilities/10011nvdThird Party Advisory
News mentions
0No linked articles in our index yet.