← Vulnerability feed

Vulnerability record · CVE-2020-8772 · published 6 February 2020

CVE-2020-8772: InfiniteWP Client WordPress plugin missing authorization allows admin login

RRevmakx · Infinitewp Client

The InfiniteWP Client plugin for WordPress before 1.9.4.5 lacks an authorization check in iwp_mmb_set_request in init.php. An attacker who knows an administrator's username can authenticate as that administrator. This is a critical authentication bypass affecting any site running an unpatched version of the plugin.

9.8 CVSS 3.1 Critical EPSS 88% · top 0.2% CWE-862 · Missing authorization
9.8CVSS 3.1 base score, v2 7.5
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no privileges or interaction required, very high EPSS, and public exploit references make this an urgent authentication bypass.

What it is

The InfiniteWP Client plugin for WordPress before 1.9.4.5 lacks an authorization check in iwp_mmb_set_request in init.php. An attacker who knows an administrator's username can authenticate as that administrator. This is a critical authentication bypass affecting any site running an unpatched version of the plugin.

Impact

An attacker gains full administrative access to the WordPress site, enabling complete control over content, users, plugins and configuration. Because the flaw is an authentication bypass, no password or prior access is required.

Attack surface

Reachable over the network through the plugin's request handling in init.php; the CVSS vector shows no privileges required and no user interaction. The only precondition stated is knowledge of an administrator username.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.88049, 99.76th percentile) and public references are tagged Exploit, indicating known public exploitation techniques. No ransomware association is documented.

What to do

  • Update the InfiniteWP Client plugin to version 1.9.4.5 or later immediately.
  • If patching is not possible, deactivate or remove the plugin until it can be updated.
  • Audit administrator accounts and rotate credentials for any account whose username may be known.
  • Restrict access to WordPress admin and plugin endpoints by IP or WAF rules where feasible.
  • Monitor for unexpected administrator logins and review user role changes.

Detection

  • Review web server and WordPress logs for authentication events against admin accounts from unexpected source IPs.
  • Hunt for requests to plugin endpoints handling iwp_mmb_set_request or init.php parameters.
  • Alert on new administrator account creation or privilege escalation shortly after suspicious logins.
  • Correlate login timestamps with plugin file access to identify exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8772 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-15004Revmakx infinitewp client injection vulnerabilityA vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown f…EPSS 1.8%5.9CVE-2023-6565Revmakx infinitewp client vulnerabilityThe InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi…EPSS 0.64%5.3CVE-2024-10585Revmakx infinitewp client path traversal vulnerabilityThe InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter…EPSS 0.65%5.3CVE-2023-2916Revmakx infinitewp client information exposure vulnerabilityThe InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.11.1 via the 'admin_no…EPSS 24%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed9.9CVE-2024-57726SimpleHelp missing authorization lets low-privilege technicians escalate to adminSimpleHelp remote support software v5.5.7 and earlier fails to properly authorize API key creation, allowing low-privilege technicians to mint API ke…KEVEPSS 67%analysed8.8CVE-2023-52163Digiever DS-2105 Pro time_tzsetup.cgi command injectionDigiever DS-2105 Pro firmware 3.1.0.71-11 exposes time_tzsetup.cgi to command injection, and the record also maps the issue to CWE-862 missing author…KEVEPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8772), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.