Infility Global

Infility Global has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 9 are fixed and 5 remain unpatched as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 5 high. 2025 was the busiest year with 8 disclosures.

The most common weakness is SQL Injection, behind 6 of the records (43%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

9 of the records (64%) have a vendor fix, while 5 remain unpatched. The oldest unresolved one dates back to 2025.

12 independent researchers contributed these findings, most of them (2) reported by Drew Webber (mcdruid). Infility Global is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

01234567891026.07.2022Today06.01.20256.5Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Update CVSS 6.5 · 06.01.20256.1Infility Global <= 2.9.8 - Reflected Cross-Site Scripting via set_type Parameter CVSS 6.1 · 06.01.202529.05.20256.5Infility Global <= 2.12.7 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 29.05.202523.06.20256.1Infility Global <= 2.13.4 - Reflected Cross-Site Scripting CVSS 6.1 · 23.06.202507.07.20256.1Infility Global <= 2.13.4 - Reflected Cross-Site Scripting CVSS 6.1 · 07.07.202514.08.20256.5Infility Global <= 2.15.34 - Authenticated (Subscriber+) Arbitrary File Download CVSS 6.5 · 14.08.202511.12.20258.8Infility Global <= 2.14.42 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 11.12.202531.12.20257.5Infility Global <= 2.15.36 - Unauthenticated SQL Injection CVSS 7.5 · 31.12.202515.01.20267.2Infility Global <= 2.15.36 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 15.01.202603.02.20267.5Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass CVSS 7.5 · 03.02.202619.05.20266.5Infility Global <= 2.15.16 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter CVSS 6.5 · 19.05.202625.06.20266.5Infility Global < 2.15.19 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 25.06.20264.9Infility Global < 2.15.20 - Authenticated (Editor+) SQL Injection CVSS 4.9 · 25.06.202615.08.20267.2Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint CVSS 7.2 · 15.08.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage64%
Open

5

Fixed

9

Get automatic notifications for all Infility Global vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2025-15268

Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass

Read the full analysis

Vulnerability Records

14 records
2026-08-15 18:15CVE-2026-10734
7.2
High
Denny Abraham Sinaga (dennyabrahamsinaga)No
2026-06-25 00:00CVE-2026-8163
6.5
Medium
TRAN THE LONGYes
2026-06-25 00:00CVE-2026-7842
4.9
Medium
Mustafa AhmedYes
2026-05-19 12:07CVE-2026-8685
6.5
Medium
oolongeyaNo
2026-02-03 19:43CVE-2025-15268
7.5
High
andrea bocchettiNo
2026-01-15 00:00CVE-2025-68864
7.2
High
Drew Webber (mcdruid)Yes
2025-12-31 00:00CVE-2025-68865
7.5
High
Drew Webber (mcdruid)Yes
2025-12-11 15:11CVE-2025-12968
8.8
High
kr0dYes
2025-08-14 00:00CVE-2025-47650
6.5
Medium
Martino SpagnuoloYes
2025-07-07 00:00CVE-2025-47652
6.1
Medium
Martino SpagnuoloYes
Showing 1–10 of 14 reports
Plugin Profile
Latestv2.16.05

Infility Global

Infility

Author

Infility

0.0(0)
0/100
Last Updated
2026-09-10 (3d ago)
Active Installs
100+
Downloads
15,479
Requires WP
5.6+
Requires PHP
7.3+
Tested up to
WP 6.8.8
Created
2022-07-26 (4y ago)

The company’s open source functional plug-ins are used to optimize the small problems of Elementor or CF7, and are already convenient for website settings.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C