PatchSiren

Infility CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM infility CVE published 2026-05-20

CVE-2026-8685

A SQL injection vulnerability in the Infility Global WordPress plugin allows authenticated attackers with Subscriber-level access or higher to extract sensitive database information. The flaw exists in the show_control_data::post_list() function, which fails to properly escape and prepare user-supplied 'orderby' and 'order' parameters. The function is registered as an admin menu page requiring only the 'r [truncated]

CRITICAL Infility CVE published 2026-01-05

CVE-2025-68865

A critical SQL injection vulnerability exists in the Infility Global plugin, affecting versions from n/a through 2.15.06. This issue allows attackers to inject malicious SQL code, potentially leading to data breaches or system compromise. The vulnerability requires immediate attention from administrators and users to prevent potential data breaches and system compromise. The CVE record and NVD entry provi [truncated]