Sploitus

CVE-2020-8772

2 known exploits for CVE-2020-8772

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

Affected products
Infinitewp Client
Revmakx Infinitewp Client
< 1.9.4.5
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
88.0% (100th percentile)
Weakness
CWE-862
NVD status
Modified
Published
2020-02-06
CVE-2020-8772 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2020-8772

Proof-of-concept code and exploit modules indexed by Sploitus