CVE-2026-6512 - Vulnerability Analysis
CriticalCVSS: 9.1Last Updated: May 14, 2026
InfusedWoo Pro - Authorization Bypass
Overview
InfusedWoo Pro WordPress plugin <= 5.1.2 contains an authorization bypass caused by improper user authorization verification, letting unauthenticated attackers delete or modify posts, pages, products, orders, and comments.
Severity & Score
Impact
Unauthenticated attackers can delete or modify content, causing data loss and disruption of site operations.
Mitigation
Update to the latest version of InfusedWoo Pro.
References
Social Media Activity(4 posts)
š“ CVE-2026-6512 - Critical (9.1) The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ... š https://www.thehackerwire.com/vulnerability/CVE-2026-6512/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postšØ CRITICAL: CVE-2026-6512 in InfusedWoo Pro (ā¤5.1.2) lets unauthenticated attackers delete posts, orders, and more on WordPress sites. No patch yet ā restrict/disable plugin & monitor vendor advisories. https://radar.offseq.com/threat/cve-2026-6512-cwe-862-missing-authorization-in-inf-277015b0 #OffSeq #WordPress #Infosec #Vuln
View original postš“ CVE-2026-6512 - Critical (9.1) The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for ... š https://www.thehackerwire.com/vulnerability/CVE-2026-6512/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postšØ CRITICAL: CVE-2026-6512 in InfusedWoo Pro (ā¤5.1.2) lets unauthenticated attackers delete posts, orders, and more on WordPress sites. No patch yet ā restrict/disable plugin & monitor vendor advisories. https://radar.offseq.com/threat/cve-2026-6512-cwe-862-missing-authorization-in-inf-277015b0 #OffSeq #WordPress #Infosec #Vuln
View original postRelated Resources
Details
- CVE ID
- CVE-2026-6512
- Severity
- Critical
- CVSS Score
- 9.1
- Type
- broken_access_control
- Status
- rejected
- EPSS
- 7.0%
- Social Posts
- 4
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N