CVE-2026-15038 PUBLISHED

InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite

Assigner: WPScan
Reserved: 08.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

Product Status

Vendor Unknown
Product InfiniteWP Client
Versions Default: unaffected
  • affected from 0 to 1.13.6 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE