Vulnerabilities (CVE)

Filtered by vendor Infinitewp Subscribe
Filtered by product Infinitewp
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28642 1 Infinitewp 1 Infinitewp 2020-11-30 7.5 HIGH 9.8 CRITICAL
In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.