Description
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or orders, mass-delete all comments on any post, and change any post's status.
Problem types
Product status
Any version
Timeline
| 2026-03-11: | Discovered |
| 2026-04-21: | Vendor Notified |
| 2026-05-13: | Disclosed |
Credits
Osvaldo Noe Gonzalez Del Rio
References
www.wordfence.com/...-b48f-49f5-ba63-276805904945?source=cve
downloads.infusedwoo.com/updater/iw5.php?changelog