PT-2026-40899 · WordPress · Infusedwoo Pro

CVE-2026-6514

·

Published

2026-05-14

·

Updated

2026-05-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions InfusedWoo Pro versions prior to 5.1.3
Description The InfusedWoo Pro plugin for WordPress allows unauthenticated attackers to perform Arbitrary File Read via the 'popup submit' endpoint. This allows web requests to be made to arbitrary locations from the web application, which can be used to query and modify information from internal services.
Recommendations Update the plugin to a version later than 5.1.2.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6514

Affected Products

Infusedwoo Pro