CVE-2026-15038

9.8

InfiniteWP · InfiniteWP Client

The InfiniteWP Client WordPress plugin fails to verify request authenticity, allowing unauthenticated attackers to hijack administrator sessions and achieve remote code execution.

Executive summary

A critical vulnerability in the InfiniteWP Client plugin allows unauthenticated attackers to hijack administrative sessions and gain full control over affected WordPress Multisite networks.

Vulnerability

This is an improper authentication vulnerability occurring within the remote-management endpoint of the plugin. Unauthenticated remote attackers can bind their own keys to the site, bypassing security controls to hijack administrator sessions.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this flaw, which grants attackers total control over the affected environment. Successful exploitation leads to a complete site takeover, unauthorized access to sensitive data, and the execution of arbitrary code, which could result in severe reputational damage and long-term security compromise.

Remediation

Immediate Action: Update the InfiniteWP Client plugin to version 1.13.6 or later immediately.

Proactive Monitoring: Monitor server access logs for unusual requests directed at the remote-management endpoint, particularly those originating from unknown or unauthorized IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious traffic patterns targeting WordPress management endpoints until the update can be applied.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub.

Analyst recommendation

Given the ease of exploitation and the potential for full system compromise, this vulnerability poses an immediate threat to any organization utilizing the InfiniteWP Client. Administrators must prioritize patching to version 1.13.6 across all affected WordPress Multisite instances to mitigate the risk of unauthorized access and remote code execution.