Vendor
The InfusedWoo Pro plugin for WordPress, in versions up to 5.1.17, contains a privilege escalation vulnerability allowing authenticated subscribers to perform unauthorized password resets for arbitrary accounts via the ajax_iwar_preview_email function.