PT-2026-51475 · WordPress · Infility Global
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Infility Global WordPress plugin versions prior to 2.15.20
Description
Authenticated attackers with Editor-level access or higher can perform time-based blind SQL injection to extract sensitive data from the database. This occurs because the plugin fails to sanitize or validate the
orderby and order parameters within the import list(), url detail(), and file detail() admin page callbacks before incorporating them into SQL queries. This issue requires the ImportData module to be enabled via the module toggle page.Recommendations
Update Infility Global WordPress plugin to version 2.15.20 or later.
As a temporary mitigation, disable the ImportData module via the module toggle page.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infility Global