PT-2026-81166 · WordPress · Infusedwoo Pro
CVE-2026-19892
·
Published
2026-08-25
·
Updated
2026-08-25
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InfusedWoo Pro versions prior to 5.1.18
Description
Low-privilege authenticated users, including those with subscriber-level access, can escalate privileges and take over accounts. The issue stems from a missing capability check in the
ajax iwar preview email() function, which relies solely on is admin() for authorization. This allows attackers to render email preview merge fields for any arbitrary email address, enabling the generation and retrieval of valid password reset links for any user, including administrators.Recommendations
Update InfusedWoo Pro to version 5.1.18 or later.
As a temporary mitigation, restrict access to the
ajax iwar preview email() function for non-administrative users.Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infusedwoo Pro