Junglewise Threat Intelligence

CVE-2026-6506: InfusedAddons InfusedWoo Pro privilege escalation in infusedwoo_gdpr_upddata

CVE-2026-6506 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: InfusedAddons InfusedWoo Pro. Vendors: InfusedAddons.

Executive brief

InfusedWoo Pro is a WordPress plugin used to integrate WooCommerce stores with the Keap CRM platform. A security flaw in the plugin allows users with basic account access (such as customers or subscribers) to grant themselves administrative control over the entire website. This could lead to a total takeover of the site, resulting in the theft of customer data, service disruption, or the installation of malicious software.

Technical details

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.1.2. The vulnerability exists within the 'infusedwoo_gdpr_upddata()' function, which fails to implement proper authorization and capability checks. Furthermore, the function does not restrict which user meta keys can be modified. An authenticated attacker with subscriber-level permissions can exploit this by updating their own 'wp_capabilities' user meta key to assign themselves the Administrator role. This is a network-based attack requiring low privileges and no user interaction.

Affected products

  • InfusedAddons InfusedWoo Pro Up to, and including, 5.1.2

Timeline

  • 2026-05-14: advisory: Initial disclosure by Wordfence and NVD publication.

References