Description
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Published: 2026-08-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The InfiniteWP Client WordPress plugin before version 1.13.6 does not correctly verify the site‑connection state and the authenticity of requests sent to its remote‑management endpoint on Multisite installations. This omission allows attackers who do not need any credentials to bind a key of their choosing, hijack an existing administrator session, and effectively take control of the entire network, resulting in the ability to execute arbitrary code on the host.

Affected Systems

WordPress sites that have the InfiniteWP Client plugin installed on a Multisite network, with any version earlier than 1.13.6. The vulnerability exists regardless of the specific WordPress version but requires that the plugin be active and that the remote‑management endpoint is reachable.

Risk and Exploitability

The vulnerability is exploitable by unauthenticated remote attackers who can reach the Multisite admin interface. Although EPSS data is not available, the severity implied by the description and the high impact of full network takeover suggests a high risk. The vulnerability is not currently listed in CISA’s KEV catalog. The lack of proper request authentication fundamentally undermines the authorization model of the plugin, allowing privilege escalation to the level of a network administrator and beyond.

Generated by OpenCVE AI on August 9, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the InfiniteWP Client plugin to version 1.13.6 or newer.
  • Restrict access to the Multisite admin interface to trusted IP addresses or disable the Multisite feature until a patch is applied.
  • Review plugin configuration for any existing unauthorized remote keys and remove them.

Generated by OpenCVE AI on August 9, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Title InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-09T06:00:14.091Z

Reserved: 2026-07-08T08:39:39.820Z

Link: CVE-2026-15038

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T08:00:04Z

Weaknesses

No weakness.