PT-2026-81166 · WordPress · Infusedwoo Pro

CVE-2026-19892

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions InfusedWoo Pro versions prior to 5.1.18
Description Low-privilege authenticated users, including those with subscriber-level access, can escalate privileges and take over accounts. The issue stems from a missing capability check in the ajax iwar preview email() function, which relies solely on is admin() for authorization. This allows attackers to render email preview merge fields for any arbitrary email address, enabling the generation and retrieval of valid password reset links for any user, including administrators.
Recommendations Update InfusedWoo Pro to version 5.1.18 or later. As a temporary mitigation, restrict access to the ajax iwar preview email() function for non-administrative users.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19892

Affected Products

Infusedwoo Pro