plugin

Infusedwoopro Vulnerabilities

5 known security issues reported for the Infusedwoopro WordPress plugin. Most recent disclosed Aug 24, 2026.

2 critical 3 high

Running Infusedwoopro on your site? Check whether your installed version is affected.

Scan your site free

InfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure

high

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users t...

CVSS:
8.8
Affected:
up to 5.1.17
Fixed in:
5.1.18
Disclosed:
Aug 24, 2026

CVE-2026-19892 on NVD →

InfusedWoo Pro <= 5.1.2 - Unauthenticated Arbitrary File Read via 'url' Parameter

high

The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify informa...

CVSS:
7.5
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
May 13, 2026

CVE-2026-6514 on NVD →

InfusedWoo Pro <= 5.1.2 - Unauthenticated Missing Authorization to Arbitrary Post Deletion via Multiple Parameters

critical

The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, p...

CVSS:
9.1
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
May 13, 2026

CVE-2026-6512 on NVD →

InfusedWoo Pro <= 5.1.2 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary User Meta Update

high

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible for...

CVSS:
8.8
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
May 13, 2026

CVE-2026-6506 on NVD →

InfusedWoo Pro <= 5.1.2 - Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe'

critical

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This makes it possible for unauthenticated attackers to create a ma...

CVSS:
9.8
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
May 13, 2026

CVE-2026-6510 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database