According to reports, two WordPress plugins, InfiniteWP Client and WP Time Capsule, were found to have serious vulnerabilities , putting approximately 320,000 sites at risk .
The vulnerabilities were discovered by researchers at WebArx. According to them, the two plugins are used to manage multiple WordPress sites as well as to create backups for files and databases. However, the vulnerabilities allow anyone to log in to an administrator account without using a password.
InfiniteWP is active on over 300,000 sites and WP Time Capsule on at least 20,000 domains.
The research team said the vulnerabilities affect all InfiniteWP versions prior to 1.9.4.5 . Attackers can exploit the vulnerabilities and bypass the password prompt . If attackers know an administrator's username , they are able to log in.

In WP Time Capsule, all versions prior to 1.21.16 are vulnerable . The vulnerability in this plugin also allows malicious hackers to gain access to administrator accounts
WebArx notified the plugin developer about the security issues on January 7th, and he responded immediately with a software update (a day later).
The researchers say that website owners should apply the update immediately as the problem is not addressed in any other way. Therefore, the patch is essential if they want to stay safe.
“The developer was very quick to respond and released the patch just one day after our initial report,” the research team said. “It’s great to see developers taking action quickly and informing their customers of any issues so they can update their systems as soon as possible.”
