CVE-2026-15038 is an authentication and trust-validation flaw in the InfiniteWP Client WordPress plugin affecting versions prior to 1.13.6 on WordPress Multisite installations. The plugin does not properly verify the site-connection state or the authenticity of requests sent to its remote-management endpoint. As a result, an unauthenticated attacker can bind an attacker-controlled key to the site, subvert the trust relationship used for remote management, hijack an administrator session, and take control of the entire multisite network. Successful compromise can ultimately lead to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-15038 affecting InfiniteWP Client on WordPress Multisite. The repo contains only two files: a README with vulnerability explanation and usage examples, and exploit.py, the main operational exploit script. The exploit is not framework-based. Its core capability is to abuse the InfiniteWP client protocol by sending a specially formatted POST body beginning with _IWP_JSON_PREFIX_ followed by base64-encoded JSON. The script generates an RSA keypair, signs InfiniteWP action data, and submits an add_site action without an activation_key. According to the included analysis, this works because of a multisite option-scope mismatch plus a loose activation-key comparison, allowing an unauthenticated attacker to register their own public key with the target. Once that trust relationship is established, the script can send additional signed InfiniteWP actions as an authenticated controller. The code structure visible from the provided content includes helper routines for RSA key generation, message signing, PEM serialization, protocol payload construction, add_site exploitation, and install_addon payload creation. The CLI supports single-target and multi-target operation, optional verbose output, configurable timeout, optional keypair persistence to local PEM files, and an RCE mode. The RCE path uses the InfiniteWP install_addon action to install and optionally activate a plugin from an arbitrary URL, which the README and usage strings position as the route to remote code execution. Operationally, this is more than a detector: it attempts full exploitation and optional post-exploitation. It targets web-accessible WordPress instances, specifically multisite deployments with vulnerable InfiniteWP Client versions prior to 1.13.6. The most fingerprintable observables are the _IWP_JSON_PREFIX_ request format, the add_site and install_addon action names, attacker-supplied plugin ZIP URLs, and locally saved iwp_priv_*.pem / iwp_pub_*.pem key files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.