Executive brief
InfusedWoo Pro is a WordPress plugin used to integrate WooCommerce stores with the Keap (formerly Infusionsoft) CRM platform. A security vulnerability in the plugin's opt-in popup feature allows unauthenticated attackers to read sensitive files from the server or interact with internal network services. This could lead to the exposure of configuration files, credentials, or other private data, potentially compromising the entire website and its connected services.
Technical details
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read and Server-Side Request Forgery (SSRF) in versions up to and including 5.1.2. The vulnerability exists within the 'popup_submit' endpoint due to insufficient input validation and authorization checks. An unauthenticated remote attacker can exploit this by sending crafted web requests to the application, forcing it to retrieve files from the local file system or make requests to internal network locations. This can be used to bypass firewalls to query or modify information from internal services. The issue was addressed in version 5.1.3 through improved authorization, input validation, and the implementation of rate limiting.
Affected products
- InfusedWoo InfusedWoo Pro up to, and including, 5.1.2
Timeline
- 2026-04-22: patched: Fixed in version 5.1.3
- 2026-05-14: disclosed: CVE published