CVE-2026-15038
RCETitle: Unauthenticated Remote Code Execution (RCE) via Session Hijacking in InfiniteWP Client
RCE
Proof Of Concept
PoC Available for CVE-2026-15038
CWE Category
NVD-CWE-noinfo
Published Date
Aug 09, 2026
Modified Date
Aug 09, 2026
Exploit Status
Available
Score
0.0
CVSS v
Exploit Probability (EPSS)
0.19%
Vulnerability Summary
CVE-2026-15038: The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Impacted Vendors
Analysis in Progress...
Reference Links
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2026-15038 Exploits & PoCs (Proof Of Concept)
GitHub
https://github.com/Polosss/By-Poloss..-..CVE-2026-15038-POC
MODIFIED
Vulnerability data updated via NVD.
Attack Vector Matrix
Awaiting Analysis
NVD/CNA metrics are not yet calculated for this intelligence record.
Affected Stack
No specific products linked.