Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Unknown InfiniteWP Client — InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .0042 35.4 —
AFFECTED
Product Versions Fixed
InfiniteWP Client unspecified —
TIMELINE
Jul 8 Reserved by WPScan
Aug 9 Published (CNA: WPScan)
Aug 10 EXPLOIT PUBLISHED — CVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added.
Description
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 8, 2026 | Reserved | Reserved by WPScan |
| August 9, 2026 | Published | Published (CNA: WPScan) |
| August 10, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-15038 (Unknown InfiniteWP Client). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Unknown | InfiniteWP Client | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-15038 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.