Executive brief
InfusedWoo Pro, a WordPress plugin used to integrate WooCommerce stores with the Keap (formerly Infusionsoft) CRM, contains a security flaw that allows unauthorized individuals to bypass security checks. An attacker can exploit this to permanently delete website content, including posts, pages, products, and customer orders. This could lead to significant data loss, disruption of business operations, and damage to the store's reputation.
Technical details
The InfusedWoo Pro plugin for WordPress fails to implement proper authorization checks on several administrative and automation endpoints. This vulnerability (CWE-862) allows unauthenticated remote attackers to perform sensitive actions such as permanently deleting arbitrary posts, pages, products, or orders, mass-deleting comments, and changing post statuses. The flaw stems from missing capability checks and insufficient validation of user permissions before executing these actions. The issue is addressed in version 5.1.3, which introduced hardening across the Automation Recipes area and other CRUD endpoints.
Affected products
- InfusedWoo InfusedWoo Pro up to, and including, 5.1.2
Timeline
- 2026-04-22: patched: Version 5.1.3 released with security hardening.
- 2026-05-14: disclosed: Vulnerability published to the CVE list.