Security Advisory

CVE-2023-2916

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-08-15 08:32:58
Last updated 2026-04-08 17:14:16
Assigner Wordfence
State PUBLISHED

Description

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the admin_notice function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.