Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint
high
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and including, 2.15.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 7.2
- Affected:
- up to 2.15.21
- Fix:
- No patched version reported
- Disclosed:
- Aug 15, 2026
CVE-2026-10734 on NVD →
Infility Global < 2.15.19 - Authenticated (Subscriber+) SQL Injection
medium
The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to 2.15.19 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to appen...
- CVSS:
- 6.5
- Affected:
- up to 2.15.19
- Fixed in:
- 2.15.19
- Disclosed:
- Jun 25, 2026
CVE-2026-8163 on NVD →
Infility Global < 2.15.20 - Authenticated (Editor+) SQL Injection
medium
The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to 2.15.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with editor-level access and above, to append ad...
- CVSS:
- 4.9
- Affected:
- up to 2.15.20
- Fixed in:
- 2.15.20
- Disclosed:
- Jun 25, 2026
CVE-2026-7842 on NVD →
Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter
medium
The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query within the show_control_data::post...
- CVSS:
- 6.5
- Affected:
- up to 2.15.16
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2026
CVE-2026-8685 on NVD →
Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass
high
The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API action in all versions up to, and including, 2.14.46. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it po...
- CVSS:
- 7.5
- Affected:
- up to 2.14.46
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2025-15268 on NVD →
Infility Global <= 2.14.49 - Unauthenticated Stored Cross-Site Scripting
high
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.14.49 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 7.2
- Affected:
- up to 2.14.49
- Fix:
- No patched version reported
- Disclosed:
- Jan 15, 2026
CVE-2025-68864 on NVD →
Infility Global <= 2.14.49 - Unauthenticated SQL Injection
high
The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.14.49 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...
- CVSS:
- 7.5
- Affected:
- up to 2.14.49
- Fix:
- No patched version reported
- Disclosed:
- Dec 31, 2025
CVE-2025-68865 on NVD →
Infility Global <= 2.14.42 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2.14.42. This is due to the `upload_file` function in the `infility_import_file` class only validating the MIME type which can be easily spoofe...
- CVSS:
- 8.8
- Affected:
- up to 2.14.42
- Fixed in:
- 2.14.43
- Disclosed:
- Dec 11, 2025
CVE-2025-12968 on NVD →
Infility Global <= 2.14.7 - Authenticated (Subscriber+) Arbitrary File Download
medium
The Infility Global plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.14.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.5
- Affected:
- up to 2.14.7
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2025
CVE-2025-47650 on NVD →
Infility Global <= 2.13.4 - Reflected Cross-Site Scripting
medium
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 2.13.4
- Fixed in:
- 2.13.5
- Disclosed:
- Jul 7, 2025
CVE-2025-47652 on NVD →
Infility Global <= 2.13.4 - Reflected Cross-Site Scripting
medium
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can success...
- CVSS:
- 6.1
- Affected:
- up to 2.13.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 23, 2025
CVE-2025-52774 on NVD →
Infility Global <= 2.12.7 - Authenticated (Subscriber+) SQL Injection
medium
The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.12.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and...
- CVSS:
- 6.5
- Affected:
- up to 2.12.7
- Fix:
- No patched version reported
- Disclosed:
- May 29, 2025
CVE-2025-47651 on NVD →
Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Update
medium
The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin opt...
- CVSS:
- 6.5
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.9
- Disclosed:
- Jan 6, 2025
CVE-2024-11496 on NVD →
Infility Global <= 2.9.8 - Reflected Cross-Site Scripting via set_type Parameter
medium
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 2.9.8
- Fixed in:
- 2.9.9
- Disclosed:
- Jan 6, 2025
CVE-2024-12290 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database