.. / CVE-2020-8772

Exploit for WordPress InfiniteWP <1.9.4.5 - Authorization Bypass (CVE-2020-8772)

Description:

WordPress InfiniteWP plugin before 1.9.4.5 for WordPress contains an authorization bypass vulnerability via a missing authorization check in iwp_mmb_set_request in init.php. An attacker who knows the username of an administrator can log in, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2020-8772.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-8772.yaml
Copy

References:

https://wpvulndb.com/vulnerabilities/10011
https://nvd.nist.gov/vuln/detail/CVE-2020-8772
https://wpscan.com/vulnerability/10011
https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/
https://github.com/ChoiSG/vwp