Description
WordPress Plugin InfiniteWP Client is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently disable a users web site by putting it in maintenance mode if admin username is known. WordPress Plugin InfiniteWP Client version 1.3.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.8 or latest
References
Related Vulnerabilities
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4193)
Moodle CVE-2022-30598 Vulnerability (CVE-2022-30598)
WordPress Plugin CardGate Payments for WooCommerce Security Bypass (3.1.15)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5866)