Infinitewp Client Revmakx Infinitewp Client

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Revmakx Infinitewp Client.

By the Year

In 2026 there have been 1 vulnerability in Revmakx Infinitewp Client with an average score of 7.6 out of ten. Last year, in 2025 Infinitewp Client had 1 security vulnerability published. At the current rates, it appears that the number of vulnerabilities last year and this year may equal out. However, the average CVE base score of the vulnerabilities in 2026 is greater by 2.30.




Year Vulnerabilities Average Score
2026 1 7.60
2025 1 5.30
2024 1 5.90
2023 1 7.50
2022 1 9.80
2021 0 0.00
2020 1 0.00

It may take a day or so for new Infinitewp Client vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Revmakx Infinitewp Client Security Vulnerabilities

InfiniteWP Client 1.13.9 Blind SQLi via Improper Neutralization
CVE-2026-74011 7.6 - High - August 20, 2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.

SQL Injection

InfiniteWP Client <=1.13.0 Path Traversal via historyID
CVE-2024-10585 5.3 - Medium - January 08, 2025

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

Directory traversal

Sensitive Data Leak in InfiniteWP Client <1.12.3 (multi-call backup)
CVE-2023-6565 5.9 - Medium - February 29, 2024

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.

Insecure Storage of Sensitive Information

Sensitive Info Exposure in InfiniteWP Client 1.11.1 via admin_notice
CVE-2023-2916 7.5 - High - August 15, 2023

The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_notice' function. This can allow authenticated attackers with subscriber-level permissions or above to extract sensitive data including configuration. It can only be exploited if the plugin has not been configured yet. If combined with another arbitrary plugin installation and activation vulnerability, it may be possible to connect a site to InfiniteWP which would make remote management possible and allow for elevation of privileges.

Information Disclosure

A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0
CVE-2016-15004 9.8 - Critical - July 23, 2022

A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.

Injection

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php
CVE-2020-8772 - February 06, 2020

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Revmakx Infinitewp Client or by Revmakx? Click the Watch button to subscribe.

Revmakx
Vendor

subscribe