PT-2026-40899 · WordPress · Infusedwoo Pro
CVE-2026-6514
·
Published
2026-05-14
·
Updated
2026-05-14
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
InfusedWoo Pro versions prior to 5.1.3
Description
The InfusedWoo Pro plugin for WordPress allows unauthenticated attackers to perform Arbitrary File Read via the 'popup submit' endpoint. This allows web requests to be made to arbitrary locations from the web application, which can be used to query and modify information from internal services.
Recommendations
Update the plugin to a version later than 5.1.2.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infusedwoo Pro