infinitewp records
4 published records for vendor infinitewp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-28642No exploit | In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attainfinitewp · infinitewp · CWE-338 | Critical9.8 | — | 2.6% | Nov 15, 2020 |
31Monitor | CVE-2014-9521No exploit | Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is seinfinitewp · infinitewp · CWE-94 | High7.5 | — | 2.3% | Jan 5, 2015 |
30Monitor | CVE-2014-9519No exploit | SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands viinfinitewp · infinitewp · CWE-89 | High7.5 | — | 1.2% | Jan 5, 2015 |
30Monitor | CVE-2014-9520No exploit | SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands infinitewp · infinitewp · CWE-89 | High7.5 | — | 1.2% | Jan 5, 2015 |
- CVE-2020-2864240Plan
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote atta
CriticalCVSS 9.8No exploitEPSS 3%infinitewp · infinitewpNov 15, 2020
- CVE-2014-952131Monitor
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is se
HighCVSS 7.5No exploitEPSS 2%infinitewp · infinitewpJan 5, 2015
- CVE-2014-951930Monitor
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 1%infinitewp · infinitewpJan 5, 2015
- CVE-2014-952030Monitor
SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5No exploitEPSS 1%infinitewp · infinitewpJan 5, 2015