What is CVE-2026-15038?
The InfiniteWP Client WordPress plugin before version 1.13.6 fails to properly verify request authenticity and site-connection state at its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key and hijack an administrator session. Immediate update to the latest version is strongly recommended.
Azərbaycanca: InfiniteWP Client WordPress plugin-in 1.13.6-dan əvvəlki versiyalarında, WordPress Multisite qurğularında uzaqdan idarəetmə endpoint-ində sorğuların həqiqiliyini və sayt bağlantı vəziyyətini düzgün yoxlamadığı üçün autentifikasiya olunmamış hücumçulara öz açarlarını bağlayaraq administrator sessiyasını ələ keçirməyə imkan verən kritik boşluqdur. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the InfiniteWP Client plugin are affected by CVE-2026-15038?
All versions of the InfiniteWP Client WordPress plugin before 1.13.6 are affected by this vulnerability.
Is authentication required for an attacker to exploit this critical vulnerability?
No, this vulnerability can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.