CVE-2026-6506Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is due to the infusedwoo_gdpr_upddata() function missing authorization and capability checks, as well as lacking restrictions on which user meta keys can be updated. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their own wp_capabilities user meta to grant themselves Administrator role privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-14); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-14: 2Mentions · 2026-06-19: 1Technical Details · 2026-05-14: 2Technical Details · 2026-06-19: 105-1406-19
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-142
Disclosure2
2026-06-191
Disclosure1
Full discourse3 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-6506. The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.2. This is… Inventory first. Panic never helps.

    Post summary

    An advisory announces CVE-2026-6506 as a privilege escalation flaw in InfusedWoo Pro up to version 5.1.2, with no proof‑of‑concept, exploit, active exploitation, patch, or false‑positive details provided.

    1000031
    337 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6506 Privilege Escalation in InfusedWoo Pro WordPress Plugin Up to 5.1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6506

    Post summary

    A new privilege escalation vulnerability (CVE-2026-6506) affecting InfusedWoo Pro WordPress plugin up to version 5.1.2 has been disclosed, with no exploit or patch details provided.

    0000055
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6506 The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6506 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post discloses a high‑severity privilege escalation vulnerability (CVE‑2026‑6506) affecting all InfusedWoo Pro plugin versions up to 5.1, provides a link to a detailed analysis, but offers no exploit, patch, or active‑attack evidence.

    0000044
    90 followersView on X

Explore more