Privilege Escalation in InfusedWoo Pro Plugin for WordPress
CVE-2026-19892

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 August 2026

What is CVE-2026-19892?

The InfusedWoo Pro plugin for WordPress presents a security flaw that allows privilege escalation through account takeover. This vulnerability arises due to the absence of a proper capability check in the 'ajax_iwar_preview_email()' function, relying solely on 'is_admin()' for authorization. As a result, low-privilege users can exploit this vulnerability to render email preview merge fields for any email address. Authenticated attackers with subscriber-level access and above can generate valid password reset links for any WordPress user, including administrators, thereby facilitating unauthorized access to accounts.

Affected Version(s)

InfusedWoo Pro 0 <= 5.1.17

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio (Os)
.