Privilege Escalation in InfusedWoo Pro Plugin for WordPress
CVE-2026-6510
What is CVE-2026-6510?
The InfusedWoo Pro plugin for WordPress is susceptible to a privilege escalation flaw due to inadequate authorization checks in versions up to and including 5.1.2. This vulnerability arises from the lack of nonce verification and capability assessments in the iwar_save_recipe() AJAX handler. Consequently, unauthenticated attackers can exploit this weakness to craft a malicious automation recipe, enabling them to trigger an HTTP POST request paired with an auto-login action. This exploitation allows any unauthorized user to access a specially crafted URL, leading to the receipt of authentication cookies for any designated user account, including that of an administrator, effectively facilitating authentication bypass and privilege escalation.
Affected Version(s)
InfusedWoo Pro 0 <= 5.1.2