WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in InfiniteWP Client

Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.

7Reported vulnerabilities
9.8Highest CVSS score
1.13.7Latest version
200,000+Active installs

What to do now

Update InfiniteWP Client to 1.13.10 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 11, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-2916 Medium 5.3 24.0% Before 1.12.1 1.12.1 August 15, 2023
CVE-2016-15004 Critical 9.8 1.7% Before 1.6.1.1 1.6.1.1 January 25, 2017
WF-9e7a1116-2bf1-4d36-a091-e0d4a9d6e1c9 Critical 9.8 1.3.7 and earlier 1.3.8 December 2, 2014
WF-a71a1a7b-6299-44c5-b686-65f214986c27 Critical 9.8 1.3.7 and earlier 1.3.8 December 2, 2014
CVE-2023-6565 Medium 5.9 0.6% Before 1.12.3.1 1.12.3.1 February 29, 2024
CVE-2024-10585 Medium 5.3 0.7% Before 1.13.1 1.13.1 January 8, 2025
CVE-2026-74011 Medium 4.9 0.2% 1.13.9 and earlier 1.13.10 August 20, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.