Infility Global
Infility Global has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 9 are fixed and 5 remain unpatched as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 5 high. 2025 was the busiest year with 8 disclosures.
The most common weakness is SQL Injection, behind 6 of the records (43%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
9 of the records (64%) have a vendor fix, while 5 remain unpatched. The oldest unresolved one dates back to 2025.
12 independent researchers contributed these findings, most of them (2) reported by Drew Webber (mcdruid). Infility Global is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-15268Infility Global <= 2.14.46 - Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass
Read the full analysisVulnerability Records
Infility Global
Author
Infility
The company’s open source functional plug-ins are used to optimize the small problems of Elementor or CF7, and are already convenient for website settings.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C