Impact
The InfiniteWP Client WordPress plugin before version 1.13.6 does not correctly verify the site‑connection state and the authenticity of requests sent to its remote‑management endpoint on Multisite installations. This omission allows attackers who do not need any credentials to bind a key of their choosing, hijack an existing administrator session, and effectively take control of the entire network, resulting in the ability to execute arbitrary code on the host.
Affected Systems
WordPress sites that have the InfiniteWP Client plugin installed on a Multisite network, with any version earlier than 1.13.6. The vulnerability exists regardless of the specific WordPress version but requires that the plugin be active and that the remote‑management endpoint is reachable.
Risk and Exploitability
The vulnerability is exploitable by unauthenticated remote attackers who can reach the Multisite admin interface. Although EPSS data is not available, the severity implied by the description and the high impact of full network takeover suggests a high risk. The vulnerability is not currently listed in CISA’s KEV catalog. The lack of proper request authentication fundamentally undermines the authorization model of the plugin, allowing privilege escalation to the level of a network administrator and beyond.
OpenCVE Enrichment