๐Ÿ” CVE Alert

CVE-2026-15038

UNKNOWN 0.0

InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

Vendor unknown
Product infinitewp client
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for unknown infinitewp client

Be the first to know when new unknown vulnerabilities affecting unknown infinitewp client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / InfiniteWP Client
0 < 1.13.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/629d655f-cdb8-4733-81d5-12fa88c32bb6/

Credits

Jakub Herman WPScan