Extension WordPress
Vulnérabilités InfusedWoo Pro
Cette page rassemble les failles publiées pour InfusedWoo Pro, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de InfusedWoo Pro
4 fiches
InfusedWoo Pro <= 5.1.2 – Unauthenticated Arbitrary File Read via 'url' Parameter
The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2 via the popup_submit. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating…
*-5.1.2
5.1.3
13/05/2026
InfusedWoo Pro <= 5.1.2 – Unauthenticated Missing Authorization to Arbitrary Post Deletion via Multiple Parameters
The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…
*-5.1.2
5.1.3
13/05/2026
InfusedWoo Pro <= 5.1.2 – Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary User Meta Update
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which…
*-5.1.2
5.1.3
13/05/2026
InfusedWoo Pro <= 5.1.2 – Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe'
The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions up to, and including, 5.1.2. This is due to missing nonce verification and capability checks in the iwar_save_recipe() AJAX handler. This…
*-5.1.2
5.1.3
13/05/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.