← back
CVE-2020-8772

CVE-2020-8772

40Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 88%
from disclosure to weapon0 days
Published on NVDFeb 6
metasploitJan 14
exploitation probability
88%top 1% of all CVEs
observed exploitation
nono source reports it
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
Affected products
n/a · n/a