Dismissed
(no matching packages found)
Activity log
- Created & dismissed (no matching packages found) suggestion
InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
References
-
https://wpscan.com/vulnerability/629d655f-cdb8-4733-81d5-12fa88c32bb6/ technical-descriptionvdb-entryexploit
Affected products
InfiniteWP Client
- <1.13.6