PT-2020-20264 · Infinitewp · Infinitewp Client

Dave Jong

·

Published

2020-02-06

·

Updated

2025-09-08

·

CVE-2020-8772

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InfiniteWP Client plugin versions prior to 1.9.4.5
Description The issue is related to a missing authorization check in the iwp mmb set request function in init.php. This allows an attacker who knows the username of an administrator to log in without proper authorization.
Recommendations For versions prior to 1.9.4.5, update to version 1.9.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the init.php file or the iwp mmb set request function to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-8772

Affected Products

Infinitewp Client