Vulnerability Report

CVE-2026-15038

RCE

Title: Unauthenticated Remote Code Execution (RCE) via Session Hijacking in InfiniteWP Client

RCE

Proof Of Concept

PoC Available for CVE-2026-15038

CWE Category NVD-CWE-noinfo
Published Date Aug 09, 2026
Modified Date Aug 09, 2026
Exploit Status Available
Score 0.0 CVSS v
Exploit Probability (EPSS)
0.19%

Vulnerability Summary

CVE-2026-15038: The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.

Impacted Vendors

Analysis in Progress...

Reference Links

Associated Attack Patterns (CAPEC)

Total: Patterns

CVE-2026-15038 Exploits & PoCs (Proof Of Concept)

GitHub https://github.com/Polosss/By-Poloss..-..CVE-2026-15038-POC
View Code
MODIFIED

Vulnerability data updated via NVD.

Attack Vector Matrix

Awaiting Analysis

NVD/CNA metrics are not yet calculated for this intelligence record.

Affected Stack

No specific products linked.