Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-15038: InfiniteWP Client WordPress Plugin: Administrator Account Hijacking on Multisite
CVE-2026-15038 · published 26 days ago
Summary
A security issue affects InfiniteWP Client, a WordPress plugin used for managing multiple sites. If not addressed, an attacker could gain control of an entire network of sites, allowing them to execute malicious code remotely. To stay secure, update the InfiniteWP Client plugin to version 1.13.6 or later.
What to do
- Update unknown infinitewp client to version 1.13.6 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | infinitewp client | < 1.13.6 |
Original advisory text
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
References
- https://wpscan.com/vulnerability/629d655f-cdb8-4733-81d5-12fa88c32bb6/ exploit vdb-entry technical-description
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published9 Aug 2026
Updated3 Sep 2026
First seen9 Aug 2026
Monitor software like this
Free during beta