๐Ÿ” CVE Alert

CVE-2024-10585

MEDIUM 5.3

InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.

CWE CWE-22
Vendor revmakx
Product infinitewp client
Published Jan 8, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for revmakx infinitewp client

Be the first to know when new medium vulnerabilities affecting revmakx infinitewp client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

revmakx / InfiniteWP Client
0 โ‰ค 1.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/4d2518f6-3647-4bee-a98c-ce7f30375a62?source=cve plugins.svn.wordpress.org: https://plugins.svn.wordpress.org/iwp-client/tags/1.13.0/debug-chart/index.php plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3202851/iwp-client/trunk/debug-chart/index.php

Credits

Villu Orav