CVE-2026-19892
8.8Infused Addons · InfusedWoo Pro
The InfusedWoo Pro plugin for WordPress is susceptible to privilege escalation through an account takeover vulnerability, allowing authenticated users to compromise accounts.
Executive summary
The InfusedWoo Pro WordPress plugin contains a critical privilege escalation vulnerability that allows authenticated attackers to perform account takeovers.
Vulnerability
This vulnerability is categorized as CWE-862: Missing Authorization. It allows a low-privileged authenticated user to manipulate account functions, leading to unauthorized account takeover.
Business impact
Successful exploitation allows an attacker to gain unauthorized access to user accounts, including administrative accounts. Given the CVSS score of 8.8, this poses a high risk of complete system compromise, data theft, and loss of organizational control over the WordPress environment.
Remediation
Immediate Action: Update the InfusedWoo Pro plugin to the latest available version beyond 5.1.17.
Proactive Monitoring: Review user account modification logs and monitor for suspicious administrative activity or unexpected changes to user privileges.
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block abnormal requests directed at account management endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a significant security risk to any WordPress site utilizing the InfusedWoo Pro plugin. Administrators should prioritize updating the plugin immediately to ensure that missing authorization checks are properly implemented and to prevent potential account takeover attempts.