Sceawere

Vulnerability Detail

CVE-2026-15038UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

InfiniteWP Client Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
1d ago
Vendor
Unknown
Product
InfiniteWP Client
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-09T06:17:16.393Z",
  "pubdate": "2026-08-09T06:17:16.393Z",
  "executiveSummary": "An authentication bypass and remote code execution vulnerability exists in the InfiniteWP Client WordPress plugin prior to version 1.13.6 when deployed in WordPress Multisite installations.\nThe vulnerability arises from improper verification of the site-connection state and lack of request authenticity validation at the remote-management endpoint.\nUnauthenticated remote threat actors can exploit this flaw to bind their own administrative keys to the network, successfully hijack an administrator session, and achieve full administrative takeover of the entire multisite network.\nThe primary impact of successful exploitation is complete system compromise, enabling attackers to execute arbitrary remote code on the underlying server.\nThis vulnerability poses a critical risk to multi-site deployments utilizing affected versions of the InfiniteWP Client plugin, as it completely bypasses standard authentication boundaries without requiring prior credentials or elevated privileges.",
  "technicalDetails": "The root cause of the vulnerability stems from insufficient validation checks regarding the site-connection state and request authenticity within the remote-management endpoint handled by the InfiniteWP Client WordPress plugin.\nSpecifically, the affected versions fail to cryptographically verify or properly authenticate inbound requests targeting the remote-management interface on WordPress Multisite architectures.\nThe vulnerable component is the remote-management handler responsible for processing site-connection routines and administrative linkage requests.\nAffected versions include all InfiniteWP Client WordPress plugin installations prior to version 1.13.6.\nExploitation requires zero authentication and no prior privileges, as the endpoint incorrectly accepts unvalidated payloads from external network vectors.\nThe attack flow proceeds as follows: First, an unauthenticated attacker sends a crafted malicious request directly to the remote-management endpoint of the target WordPress Multisite installation.\nSecond, because the plugin fails to properly verify the site-connection state or authenticate the incoming payload, the application processes the request as legitimate.\nThird, the attacker binds their own unauthorized administrative key to the site connection, establishing persistent unauthorized access.\nFourth, utilizing the newly bound administrative key, the attacker initiates and hijacks a legitimate administrator session within the multisite network.\nFinally, leveraging the hijacked administrative privileges, the attacker executes arbitrary remote code across the network, leading to complete system takeover and compromise of the underlying infrastructure."
}
CVE-2026-15038: InfiniteWP Client Authentication Bypass (CRITICAL Severity, CVSS: 9.8) - Sceawere