Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Critical

Authentication Bypass and Privilege Escalation in InfusedWoo Pro for WordPress

IdentifiersCVE-2026-6510CWE-862· Missing Authorization

CVE-2026-6510 is a privilege-escalation vulnerability in the InfusedWoo Pro plugin for WordPress affecting all versions up to and including 5.1.2. The flaw is caused by missing nonce verification and missing capability checks in the iwar_save_recipe() AJAX handler. Because the handler does not properly enforce authorization, an unauthenticated attacker can create a malicious automation recipe that combines an HTTP POST trigger with an auto-login action. This recipe can then be used to cause the application to issue authentication cookies for an arbitrary targeted user account, including an administrator, resulting in complete authentication bypass.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated attacker to obtain authenticated session cookies for any chosen account, including highly privileged accounts such as administrator. This results in full authentication bypass and privilege escalation to the targeted user context. Given the stated CVSS characteristics, compromise can have high impact on confidentiality, integrity, and availability, as the attacker can act with the permissions of the impersonated account.

Mitigation

If you can’t patch tonight, do this now.

If an updated version is not immediately available, disable or remove the InfusedWoo Pro plugin, or specifically disable access to the vulnerable AJAX functionality if operationally feasible. Restrict unauthenticated access to WordPress AJAX endpoints where possible, monitor for unauthorized creation of automation recipes, and review for suspicious auto-login or HTTP POST trigger configurations. Because exploitation can yield valid authentication cookies for privileged users, rotate sessions and review administrator accounts if compromise is suspected.

Remediation

Patch, then assume compromise.

Update InfusedWoo Pro to a version newer than 5.1.2 once a vendor fix is available. The vulnerable iwar_save_recipe() AJAX handler should enforce proper authorization by implementing nonce verification and capability checks before allowing recipe creation or modification. Any functionality that can create automation flows capable of triggering auto-login behavior should be restricted to appropriately authorized users only.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity8

Community discussion across Reddit, Mastodon, and other social sources.