The InfiniteWP Client WordPress plugin before 1.13.6 does...
Critical severity
Unreviewed
Published
Aug 9, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published by the National Vulnerability Database
Aug 9, 2026
Published to the GitHub Advisory Database
Aug 9, 2026
Last updated
Aug 10, 2026
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
References