InfusedWoo Pro Plugin Has Critical Vulnerability
The InfusedWoo Pro plugin, version 5.1.2 and earlier, contains a critical vulnerability (CVSS 9.8) due to missing authorization checks in the iwar_save_recipe() function. This allows attackers to bypass authentication and escalate privileges to administrator level.
Topics
Developing
- 863d Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore.
- 863d Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- 863d Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est.
- 863d Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium.
Sources · 7 independent
Polskie Radio 1
“InfusedWoo Pro Plugin Has Critical Vulnerability”
Unlock the full story
Get a Pro subscription or above to see the live story progression and the full list of independent sources confirming each event as they happen.
Log in to upgrade