Sceawere
Vulnerability Detail
CVE-2026-15038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
InfiniteWP Client Authentication Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 1d ago
- Vendor
- Unknown
- Product
- InfiniteWP Client
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-09T06:17:16.393Z",
"pubdate": "2026-08-09T06:17:16.393Z",
"executiveSummary": "An authentication bypass and remote code execution vulnerability exists in the InfiniteWP Client WordPress plugin prior to version 1.13.6 when deployed in WordPress Multisite installations.\nThe vulnerability arises from improper verification of the site-connection state and lack of request authenticity validation at the remote-management endpoint.\nUnauthenticated remote threat actors can exploit this flaw to bind their own administrative keys to the network, successfully hijack an administrator session, and achieve full administrative takeover of the entire multisite network.\nThe primary impact of successful exploitation is complete system compromise, enabling attackers to execute arbitrary remote code on the underlying server.\nThis vulnerability poses a critical risk to multi-site deployments utilizing affected versions of the InfiniteWP Client plugin, as it completely bypasses standard authentication boundaries without requiring prior credentials or elevated privileges.",
"technicalDetails": "The root cause of the vulnerability stems from insufficient validation checks regarding the site-connection state and request authenticity within the remote-management endpoint handled by the InfiniteWP Client WordPress plugin.\nSpecifically, the affected versions fail to cryptographically verify or properly authenticate inbound requests targeting the remote-management interface on WordPress Multisite architectures.\nThe vulnerable component is the remote-management handler responsible for processing site-connection routines and administrative linkage requests.\nAffected versions include all InfiniteWP Client WordPress plugin installations prior to version 1.13.6.\nExploitation requires zero authentication and no prior privileges, as the endpoint incorrectly accepts unvalidated payloads from external network vectors.\nThe attack flow proceeds as follows: First, an unauthenticated attacker sends a crafted malicious request directly to the remote-management endpoint of the target WordPress Multisite installation.\nSecond, because the plugin fails to properly verify the site-connection state or authenticate the incoming payload, the application processes the request as legitimate.\nThird, the attacker binds their own unauthorized administrative key to the site connection, establishing persistent unauthorized access.\nFourth, utilizing the newly bound administrative key, the attacker initiates and hijacks a legitimate administrator session within the multisite network.\nFinally, leveraging the hijacked administrative privileges, the attacker executes arbitrary remote code across the network, leading to complete system takeover and compromise of the underlying infrastructure."
}