Executive brief
The InfusedWoo Pro plugin for WordPress, which integrates WooCommerce with the Keap CRM, contains a critical security flaw that allows unauthorized individuals to take over user accounts. By exploiting a weakness in how the plugin handles automation 'recipes,' an attacker can create a malicious link that automatically logs them into any account, including those with administrator privileges. This could lead to a total compromise of the website, theft of customer data, and disruption of business operations.
Technical details
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. The root cause is a lack of nonce verification and capability checks within the iwar_save_recipe() AJAX handler. An unauthenticated remote attacker can exploit this to create a malicious automation recipe that links an HTTP POST trigger to an auto-login action. By inducing a visit to a specifically crafted URL, the attacker can obtain authentication cookies for any targeted user, including administrators, resulting in a complete authentication bypass and full site takeover.
Affected products
- Infused Addons InfusedWoo Pro up to, and including, 5.1.2
Timeline
- 2026-05-14: disclosed: Vulnerability published to the CVE list and NVD.