{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-17576","assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","state":"PUBLISHED","assignerShortName":"Wordfence","dateReserved":"2026-07-27T15:27:13.910Z","datePublished":"2026-09-18T06:38:51.870Z","dateUpdated":"2026-09-18T14:31:43.041Z"},"containers":{"cna":{"providerMetadata":{"orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence","dateUpdated":"2026-09-18T06:38:51.870Z"},"affected":[{"vendor":"revmakx","product":"InfiniteWP Client","versions":[{"version":"0","status":"affected","lessThanOrEqual":"1.13.9","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due to insufficient escaping on the array-key names supplied in the JSON request body before use in a SQL statement: IWP_MMB_Comment::get_comments() calls extract() on $args (which silently skips keys that are not valid PHP variable names) but a second foreach($args as $checkbox => $checkbox_val) processes every key, strips the 'iwp_get_comments_' prefix with str_replace(), wraps the remainder in single quotes, and imploded it into an IN(...) clause that is executed via $wpdb->get_results() with no prepare(). Because the request body is read from php://input and JSON-decoded, wp_magic_quotes() never touches the data, so quote characters in keys pass through unaltered. This makes it possible for authenticated attackers, with administrator-level access and above (an administrator can register their own public key via add_site using the plugin's WP-admin-generated activation_key and then issue signed get_comments requests), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"title":"InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key","references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/05c50442-570b-45cf-816a-c7a5b712ba21?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/iwp-client/tags/1.13.6/addons/comments/comments.class.php#L80"},{"url":"https://plugins.trac.wordpress.org/browser/iwp-client/tags/1.13.6/addons/comments/comments.class.php#L71"},{"url":"https://plugins.trac.wordpress.org/browser/iwp-client/tags/1.13.6/addons/comments/comments.class.php#L57"},{"url":"https://plugins.trac.wordpress.org/browser/iwp-client/tags/1.13.6/init.php#L1651"},{"url":"https://plugins.trac.wordpress.org/browser/iwp-client/tags/1.13.6/init.php#L131"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3655042%40iwp-client&new=3655042%40iwp-client"}],"problemTypes":[{"descriptions":[{"lang":"en","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","cweId":"CWE-89","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM"}}],"credits":[{"lang":"en","type":"finder","value":"Wordfence PRISM"}],"timeline":[{"time":"2026-09-17T18:35:29.000Z","lang":"en","value":"Disclosed"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-17576","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-09-18T14:18:10.437275Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-18T14:31:43.041Z"}}]}}