Product
high
advisory
Privilege Escalation in InfusedWoo Pro WordPress Plugin
1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress, in versions up to 5.1.17, contains a privilege escalation vulnerability allowing authenticated subscribers to perform unauthorized password resets for arbitrary accounts via the ajax_iwar_preview_email function.
InfusedWoo Pro
wordpress
privilege-escalation
web-application
1t
1c
high
threat
InfusedWoo Pro WordPress Plugin Arbitrary File Read Vulnerability (CVE-2026-6514)
2 rules 1 TTP 1 CVEThe InfusedWoo Pro plugin for WordPress is vulnerable to arbitrary file read in versions up to 5.1.2, allowing unauthenticated attackers to make web requests to arbitrary locations, potentially querying and modifying information from internal services.
InfusedWoo Pro
cve
wordpress
plugin
arbitrary file read
ssrf
2r
1t
1c