PT-2026-51475 · WordPress · Infility Global

·

CVE-2026-7842

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Infility Global WordPress plugin versions prior to 2.15.20
Description Authenticated attackers with Editor-level access or higher can perform time-based blind SQL injection to extract sensitive data from the database. This occurs because the plugin fails to sanitize or validate the orderby and order parameters within the import list(), url detail(), and file detail() admin page callbacks before incorporating them into SQL queries. This issue requires the ImportData module to be enabled via the module toggle page.
Recommendations Update Infility Global WordPress plugin to version 2.15.20 or later. As a temporary mitigation, disable the ImportData module via the module toggle page.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-7842

Affected Products

Infility Global