Privilege Escalation in InfusedWoo Pro Plugin for WordPress
CVE-2026-6510

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 May 2026

What is CVE-2026-6510?

The InfusedWoo Pro plugin for WordPress is susceptible to a privilege escalation flaw due to inadequate authorization checks in versions up to and including 5.1.2. This vulnerability arises from the lack of nonce verification and capability assessments in the iwar_save_recipe() AJAX handler. Consequently, unauthenticated attackers can exploit this weakness to craft a malicious automation recipe, enabling them to trigger an HTTP POST request paired with an auto-login action. This exploitation allows any unauthorized user to access a specially crafted URL, leading to the receipt of authentication cookies for any designated user account, including that of an administrator, effectively facilitating authentication bypass and privilege escalation.

Affected Version(s)

InfusedWoo Pro 0 <= 5.1.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio
.