Privilege Escalation in InfusedWoo Pro Plugin for WordPress
CVE-2026-19892
8.8HIGH
What is CVE-2026-19892?
The InfusedWoo Pro plugin for WordPress presents a security flaw that allows privilege escalation through account takeover. This vulnerability arises due to the absence of a proper capability check in the 'ajax_iwar_preview_email()' function, relying solely on 'is_admin()' for authorization. As a result, low-privilege users can exploit this vulnerability to render email preview merge fields for any email address. Authenticated attackers with subscriber-level access and above can generate valid password reset links for any WordPress user, including administrators, thereby facilitating unauthorized access to accounts.
Affected Version(s)
InfusedWoo Pro 0 <= 5.1.17