The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infused Addons
Infused Addons infusedwoo Pro Wordpress Wordpress wordpress |
|
| Vendors & Products |
Infused Addons
Infused Addons infusedwoo Pro Wordpress Wordpress wordpress |
Tue, 25 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due to a missing capability check in the `ajax_iwar_preview_email()` function, which uses `is_admin()` as its only authorization check and allows low-privilege users to render email preview merge fields for an arbitrary email address. This makes it possible for authenticated attackers, with subscriber-level access and above, to generate and retrieve a valid password reset link for any WordPress user, including administrators, enabling account takeover. | |
| Title | InfusedWoo Pro <= 5.1.18 - Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-25T03:27:05.993Z
Reserved: 2026-08-14T18:42:04.951Z
Link: CVE-2026-19892
No data.
Status : Received
Published: 2026-08-25T04:18:10.770
Modified: 2026-08-25T04:18:10.770
Link: CVE-2026-19892
No data.
OpenCVE Enrichment
Updated: 2026-08-25T05:00:11Z