Junglewise Threat Intelligence

CVE-2026-74011: revmakx InfiniteWP Client SQL injection vulnerability

CVE-2026-74011 · Severity: high · CVSS 7.6 · Published 2026-08-20

Executive brief

InfiniteWP Client is a WordPress plugin used to manage multiple WordPress sites remotely from a central dashboard. A SQL injection vulnerability in the plugin allows attackers with administrator privileges to read, modify, or delete the entire database, including user accounts and sensitive data.

Technical details

This is a SQL injection vulnerability (CWE-89) in revmakx InfiniteWP Client versions through 1.13.9 that allows blind SQL injection attacks. The vulnerability requires administrator-level privileges to exploit. By injecting malicious SQL commands through improperly sanitized input, an attacker can query, modify, or delete database records. The vulnerability has been patched in version 1.13.10 and later. No evidence of active exploitation in the wild has been reported as of the advisory date.

Affected products

  • revmakx InfiniteWP Client through 1.13.9

Timeline

  • 2026-07-16: disclosed: Reported to Patchstack by Ananda Dhakal
  • 2026-08-20: advisory: Published by Patchstack and assigned CVE-2026-74011
  • 2026-08-20: patched: Fix available in version 1.13.10

References