CVE-2026-15038
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
| Vendor | unknown |
| Product | infinitewp client |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown infinitewp client
Be the first to know when new unknown vulnerabilities affecting unknown infinitewp client are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / InfiniteWP Client
0 < 1.13.6
References
Credits
Jakub Herman WPScan