The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-09 06:17
Updated : 2026-08-26 16:31
NVD link : CVE-2026-15038
Mitre link : CVE-2026-15038
CVE.ORG link : CVE-2026-15038
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
