Executive brief
InfiniteWP Client is a WordPress plugin used to manage multiple WordPress sites remotely from a central dashboard. A SQL injection vulnerability in the plugin allows attackers with administrator privileges to read, modify, or delete the entire database, including user accounts and sensitive data.
Technical details
This is a SQL injection vulnerability (CWE-89) in revmakx InfiniteWP Client versions through 1.13.9 that allows blind SQL injection attacks. The vulnerability requires administrator-level privileges to exploit. By injecting malicious SQL commands through improperly sanitized input, an attacker can query, modify, or delete database records. The vulnerability has been patched in version 1.13.10 and later. No evidence of active exploitation in the wild has been reported as of the advisory date.
Affected products
- revmakx InfiniteWP Client through 1.13.9
Timeline
- 2026-07-16: disclosed: Reported to Patchstack by Ananda Dhakal
- 2026-08-20: advisory: Published by Patchstack and assigned CVE-2026-74011
- 2026-08-20: patched: Fix available in version 1.13.10